CVE-2025-3928

Commvault Web Server has an unspecified vulnerability that can be exploited by a remote, authenticated attacker. According to the Commvault advisory: "Webservers can be compromised through bad actors creating and executing webshells." Fixed in version 11.36.46, 11.32.89, 11.28.141, and 11.20.217 for Windows and Linux platforms. This vulnerability was added to the CISA Known Exploited Vulnerabilities (KEV) Catalog on 2025-04-28.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:commvault:commvault:*:*:*:*:*:*:*:*
cpe:2.3:a:commvault:commvault:*:*:*:*:*:*:*:*
cpe:2.3:a:commvault:commvault:*:*:*:*:*:*:*:*
cpe:2.3:a:commvault:commvault:*:*:*:*:*:*:*:*
OR cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

31 Oct 2025, 21:59

Type Values Removed Values Added
References () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-3928 - () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-3928 - US Government Resource

Information

Published : 2025-04-25 16:15

Updated : 2025-10-31 21:59


NVD link : CVE-2025-3928

Mitre link : CVE-2025-3928

CVE.ORG link : CVE-2025-3928


JSON object : View

Products Affected

microsoft

  • windows

linux

  • linux_kernel

commvault

  • commvault