During the brief window between installation and the first administrator login, remote attackers may exploit the default credential to gain admin control. This is limited to the setup phase, before any jobs have been configured.
Metrics
Affected Vendors & Products
References
History
Wed, 10 Sep 2025 16:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An issue was discovered in Commvault before 11.36.60. During the brief window between installation and the first administrator login, remote attackers may exploit the default credential to gain admin control. This is limited to the setup phase, before any jobs have been configured. | During the brief window between installation and the first administrator login, remote attackers may exploit the default credential to gain admin control. This is limited to the setup phase, before any jobs have been configured. |
Thu, 21 Aug 2025 14:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Commvault commvault
|
|
CPEs | cpe:2.3:a:commvault:commvault:*:*:*:*:*:*:*:* | |
Vendors & Products |
Commvault commvault
|
|
Metrics |
cvssV3_1
|
Thu, 21 Aug 2025 12:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Commvault
Commvault commcell |
|
Vendors & Products |
Commvault
Commvault commcell |
Wed, 20 Aug 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 20 Aug 2025 03:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An issue was discovered in Commvault before 11.36.60. During the brief window between installation and the first administrator login, remote attackers may exploit the default credential to gain admin control. This is limited to the setup phase, before any jobs have been configured. | |
Title | Vulnerability in Initial Administrator Login Process | |
Weaknesses | CWE-257 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: mitre
Published: 2025-08-20T03:22:08.764Z
Updated: 2025-09-10T15:54:49.968Z
Reserved: 2025-08-19T18:25:57.338Z
Link: CVE-2025-57789

Updated: 2025-08-20T13:31:13.038Z

Status : Modified
Published: 2025-08-20T04:16:03.847
Modified: 2025-09-10T16:15:40.353
Link: CVE-2025-57789

No data.