Back to Database
Status published
Critical
CVE-2017-3195
Commvault Edge Communication Service (cvd) prior to version 11 SP7...
Vulnerability Description
Commvault Edge Communication Service (cvd) prior to version 11 SP7 or version 11 SP6 with hotfix 590 is prone to a stack-based buffer overflow vulnerability that could lead to arbitrary code execution with administrative privileges.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2017-3195
Credits & Attribution
No credits recorded in the NVD database.
References
More from Commvault
View All →CVE-2025-57791
Argument Injection Vulnerability in CommServe
Medium
6.9
CVE-2025-57790
Path Traversal Vulnerability
High
8.7
CVE-2025-57789
Vulnerability in Initial Administrator Login Process
Medium
5.3
CVE-2025-57788
Unauthorized API Access Risk
Medium
6.9
CVE-2025-3928
Commvault Web Server unspecified vulnerability
High
8.7
Affected Vendor
Commvault
View all reports →Affected Software
Service Pack 6
Vulnerable Versions:
Version 11 prior to SP7, version 11 SP6 prior to hotfix 590
Timeline
Official Publish:
December 15th, 2017
Last Modified:
August 5th, 2024
Added to House:
July 20th, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H