kb.commvault.comConfirmation
http://kb.commvault.com/article/SEC0013 CVE-2017-3195
CRITICAL
CommVault Edge 11 SP6 - Stack Buffer Overflow (PoC)
Record summary
CVE-2017-3195 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit.
Description
Commvault Edge Communication Service (cvd) prior to version 11 SP7 or version 11 SP6 with hotfix 590 is prone to a stack-based buffer overflow vulnerability that could lead to arbitrary code execution with administrative privileges.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Service Pack 6Browse Commvault / Service Pack 6 | CVE List | Version 11 prior to SP7 | affected |
| version 11 SP6 prior to hotfix 590 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBCommVault Edge 11 SP6 - Stack Buffer Overflow (PoC)ExploitDB exploitby redr2eNot analyzed1 file
References
6redr2e.com
http://redr2e.com/commvault-edge-cve-2017-3195 96941vdb entry
http://www.securityfocus.com/bid/96941 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2017-3195 41823exploit
https://www.exploit-db.com/exploits/41823 VU#214283Third-party advisory
https://www.kb.cert.org/vuls/id/214283