Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
A Command Injection issue was discovered in ContentStore/Base/CVDataPipe.dll in Commvault before v11 SP6. A certain message parsing function inside the Commvault service does not properly validate the input of an incoming string before passing it to CreateProcess. As a result, a specially crafted message can inject commands that will be executed on the target operating system. Exploitation of this vulnerability does not require authentication and can lead to SYSTEM level privilege on any system running the cvd daemon. This is a different vulnerability than CVE-2017-3195.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Commvault 命令注入漏洞
Vulnerability Description
Commvault是美国Commvault公司的一套基于Simpana(一体化软件平台)为终端用户提供数据自动保护和即时访问等功能的软件。 Commvault 11 SP6之前版本中的ContentStore/Base/CVDataPipe.dll文件存在命令注入漏洞,该漏洞源于在将进入的字符串传递到CreateProcess之前,Commvault服务中的消息解析函数没有正确的验证输入。攻击者可借助特制的消息利用该漏洞在目标操作系统上注入并执行命令。
CVSS Information
N/A
Vulnerability Type
N/A