CVE-2025-57789
Severity CVSS v4.0:
MEDIUM
Type:
CWE-257
Storing Passwords in a Recoverable Format
Publication date:
20/08/2025
Last modified:
10/09/2025
Description
During the brief window between installation and the first administrator login, remote attackers may exploit the default credential to gain admin control. This is limited to the setup phase, before any jobs have been configured.
Impact
Base Score 4.0
5.30
Severity 4.0
MEDIUM
Base Score 3.x
5.40
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:commvault:commvault:*:*:*:*:*:*:*:* | 11.36.60 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



