Rule Category

SERVER-OTHER -- Snort has detected traffic exploiting vulnerabilities in a server in the network.

Alert Message

SERVER-OTHER Commvault Communications Service command injection attempt

Rule Explanation

This event is generated when command injection is attempted in Commvault V11 SP5 and prior cvd.exe service running on TCP port 8400. Impact: Attempted Administrator Privilege Gain Details: The message type 9 in Commvault V11 SP5 and prior for cvd.exe service is vulnerable to command injection attack. Based on the public metasploit modules for this vuln; the cvd.exe executes the commands when the input data is more than 346 bytes. This exploit is tested on Windows system only. Ease of Attack: Simple. Attacker can use the public exploit module to exploit this vuln. As the cvd.exe is running with \SYSTEM level priv the commands can be executed with \SYSTEM

What To Look For

No information provided

Known Usage

No public information

False Positives

No known false positives

Contributors

Cisco Talos Intelligence Group

Rule Groups

No rule groups

CVE

None

Additional Links

Rule Vulnerability

No information provided

CVE Additional Information

This product uses data from the NVD API but is not endorsed or certified by the NVD.

None