← back
CVE-2021-34993criticalobserved exploitationCWE-287

CVE-2021-34993

50Vexday Risk Score

Prioritize patching. It exploitation observed by VulnCheck.

ssvc Actcvss 9.8epss 5.4%
from disclosure to weapon
Published on NVDJan 13
VulnCheck+739d
exploitation probability
5.4%top 8% of all CVEs
observed exploitation
yesVulnCheck
This vulnerability allows remote attackers to bypass authentication on affected installations of Commvault CommCell 11.22.22. Authentication is not required to exploit this vulnerability. The specific flaw exists within the CVSearchService service. The issue results from the lack of proper validation prior to authentication. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-13706.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
Commvault · CommCell