Impact
CommServe contains a heap-based buffer overflow that can cause the service to crash, resulting in a denial of service that affects all users of the affected CommServe server. No code execution or data theft is implied by the description.
Affected Systems
The vulnerability affects Commvault Cloud's CommServe component; the advisory does not specify exact versions but recommends upgrading to the latest maintenance release. All customers running the affected CommServe should check their current release and apply the vendor‑supplied patch.
Risk and Exploitability
The CVSS score of 8.7 classifies this flaw as high severity, and the absence of an EPSS score suggests limited publicly available exploitation data. Based on the description, it is inferred that the vulnerability could potentially be exploited from outside the organization if the CommServe service is reachable over the network, although the description does not specify authentication requirements. As the flaw leads to a critical service disruption, it is prudent to treat this as a high‑risk condition.
OpenCVE Enrichment