Impact
CommServe contains a stack-based buffer overflow that can corrupt stack memory and crash the service, resulting in loss of availability. The flaw is caused by handling a buffer without adequate bounds checking. The CVSS score of 8.7 indicates a high severity incident based on the potential for uncontrolled memory corruption.
Affected Systems
The vulnerability affects Commvault Cloud products, specifically the CommServe component. The solution is to upgrade to the resolved maintenance release of CommServe, as detailed in the vendor advisory. No further product or version specifics are provided in the CVE record.
Risk and Exploitability
The CVSS rating of 8.7 reflects significant risk, but the EPSS score is not available, leaving exploit probability uncertain. The vulnerability is not listed in the CISA KEV catalog, suggesting it has not yet been actively exploited. The attack vector is not explicitly documented, but the description implies that an attacker would need to deliver a crafted input to the CommServe service; the particular channel (authenticated or unauthenticated) and method are inferred rather than stated.
OpenCVE Enrichment