Back
CVE-2017-3195
CRITICAL
Commvault Edge Communication Service (cvd) prior to version 11 SP7 or version 11 SP6 with hotfix 590 is prone to a stack-based buffer overflow vulnerability that could lead to arbitrary code execution with administrative privileges.
Published: Dec 16, 2017
Modified: Jun 17, 2026
CWE-121
CWE-119
CVSS Metrics
CVSSv3
Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products (7)
| Vendor | Product | Version |
|---|---|---|
| commvault | edge | 11.0.0 |
| commvault | edge | 11.0.0 |
| commvault | edge | 11.0.0 |
| commvault | edge | 11.0.0 |
| commvault | edge | 11.0.0 |
| commvault | edge | 11.0.0 |
| commvault | edge | 11.0.0 |
GitHub Security Advisory GHSA-h4f8-5wh7-64hg
Commvault Edge Communication Service (cvd) prior to version 11 SP7 or version 11 SP6 with hotfix...
References (10)
- http://kb.commvault.com/article/SEC0013 Patch, Vendor Advisory
- http://redr2e.com/commvault-edge-cve-2017-3195/ Third Party Advisory
- http://www.securityfocus.com/bid/96941 Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/41823/ Exploit, Third Party Advisory, VDB Entry
- https://www.kb.cert.org/vuls/id/214283 Third Party Advisory, US Government Resource
- http://kb.commvault.com/article/SEC0013 Patch, Vendor Advisory
- http://redr2e.com/commvault-edge-cve-2017-3195/ Third Party Advisory
- http://www.securityfocus.com/bid/96941 Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/41823/ Exploit, Third Party Advisory, VDB Entry
- https://www.kb.cert.org/vuls/id/214283 Third Party Advisory, US Government Resource
Risk Scores
CVSS Score
9.8 / 10
EPSS Score
21.39%
Top 3% most likely to be exploited
Threat Score
45.6 / 100
Data Sources
NVD
EPSS
GitHub