« Volver al listado

CVE-2017-3195

Estado: ModificadaCrítica (9.8)—

Commvault Edge Communication Service (cvd) prior to version 11 SP7 or version 11 SP6 with hotfix 590 is prone to a stack-based buffer overflow vulnerability that could lead to arbitrary code execution with administrative privileges.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2017-3195",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 10,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "LOW",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "cret@cert.org",
      "affectedData": [
        {
          "vendor": "Commvault",
          "product": "Service Pack 6",
          "versions": [
            {
              "status": "affected",
              "version": "Version 11 prior to SP7"
            },
            {
              "status": "affected",
              "version": "version 11 SP6 prior to hotfix 590"
            }
          ]
        }
      ]
    }
  ],
  "published": "2017-12-16T02:29:10.510",
  "references": [
    {
      "url": "http://kb.commvault.com/article/SEC0013",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "cret@cert.org"
    },
    {
      "url": "http://redr2e.com/commvault-edge-cve-2017-3195/",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "cret@cert.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/96941",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "cret@cert.org"
    },
    {
      "url": "https://www.exploit-db.com/exploits/41823/",
      "tags": [
        "Exploit",
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "cret@cert.org"
    },
    {
      "url": "https://www.kb.cert.org/vuls/id/214283",
      "tags": [
        "Third Party Advisory",
        "US Government Resource"
      ],
      "source": "cret@cert.org"
    },
    {
      "url": "http://kb.commvault.com/article/SEC0013",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://redr2e.com/commvault-edge-cve-2017-3195/",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/96941",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.exploit-db.com/exploits/41823/",
      "tags": [
        "Exploit",
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.kb.cert.org/vuls/id/214283",
      "tags": [
        "Third Party Advisory",
        "US Government Resource"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "cret@cert.org",
      "description": [
        {
          "lang": "en",
          "value": "CWE-121"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-119"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Commvault Edge Communication Service (cvd) prior to version 11 SP7 or version 11 SP6 with hotfix 590 is prone to a stack-based buffer overflow vulnerability that could lead to arbitrary code execution with administrative privileges."
    },
    {
      "lang": "es",
      "value": "Commvault Edge Communication Service (cvd) en su versión 11 SP7 o la versión 11 SP6 con hotfix 590 es vulnerable a un desbordamiento de búfer basado en pila, lo que puede conducir a una ejecución de código arbitrario con privilegios de administrador."
    }
  ],
  "lastModified": "2026-06-17T01:17:42.657",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:commvault:edge:11.0.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "09F02BA3-8D57-402A-9574-3C13D2BEB3BA"
            },
            {
              "criteria": "cpe:2.3:a:commvault:edge:11.0.0:service_pack1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CCC6B185-B3E2-41DF-8317-E02DFF74DE8B"
            },
            {
              "criteria": "cpe:2.3:a:commvault:edge:11.0.0:service_pack2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E5EFF9BD-DB8D-4E26-A2AB-E0A122489E1C"
            },
            {
              "criteria": "cpe:2.3:a:commvault:edge:11.0.0:service_pack3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3623D97D-E940-45EB-A600-CB54C29CA1BC"
            },
            {
              "criteria": "cpe:2.3:a:commvault:edge:11.0.0:service_pack4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BA4625D2-D983-41D7-9C44-E1E8725D7393"
            },
            {
              "criteria": "cpe:2.3:a:commvault:edge:11.0.0:service_pack5:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "926387BA-0A76-459B-9887-37B2FA09ACC8"
            },
            {
              "criteria": "cpe:2.3:a:commvault:edge:11.0.0:service_pack6:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "495FFD14-6151-4778-B5F6-979F48A79394"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cret@cert.org"
}