CVE-2017-3195
CRITICALCommvault Edge - Memory Corruption
Title source: ruleDescription
Commvault Edge Communication Service (cvd) prior to version 11 SP7 or version 11 SP6 with hotfix 590 is prone to a stack-based buffer overflow vulnerability that could lead to arbitrary code execution with administrative privileges.
Exploits (1)
References (5)
Scores
CVSS v3
9.8
EPSS
0.4623
EPSS Percentile
97.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-119
CWE-121
Status
published
Products (3)
commvault/edge
11.0.0 (7 CPE variants)
Commvault/Service Pack 6
Version 11 prior to SP7
Commvault/Service Pack 6
version 11 SP6 prior to hotfix 590
Published
Dec 16, 2017
Tracked Since
Feb 18, 2026