Impact
CommServe has a flaw that allows an attacker to bypass authentication, which can be used to access data they should not see. The vulnerability is an authentication bypass that leads to information disclosure. It could enable an attacker to read restricted application data and potentially other system configuration details, compromising confidentiality and integrity of stored data. The inclusion of CWE‑288 suggests that the flaw may also result in information leakage or inadequate logging of the unauthorized access.
Affected Systems
The affected product is CommVault Cloud’s CommServe component. The advisory advises users to update to the latest maintenance release to address the issue. No specific version numbers are listed in the advisory.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity, and the advisory notes that no EPSS score is available, so the exploitation probability is unknown. The vulnerability is not listed in the CISA KEV catalog, suggesting that it has not yet been widely exploited in the wild. The likely attack vector, based on the description, is a legitimate user authentication bypass that permits unauthorized access to the CommServe interface and the data it exposes.
OpenCVE Enrichment