🚨 Two Critical Pre-Auth RCE Chains Discovered in CommVault Enterprise Backup Solutions
(🧵Thread)
Even during the slow summer months when most people are on vacation, the Crowdsec team thoroughly follows the recently disclosed vulnerabilities. This week, we focus on another brilliant discovery from WatchTowr Labs (we can’t shout them out enough), which disclosed two critical vulnerabilities in the CommVault solution for enterprise Backup and Replication. These vulnerabilities allow unauthenticated attackers to achieve remote code execution on enterprise backup infrastructure, the digital equivalent of breaking into Fort Knox through the gift shop.
(🧵1/7)