In CommCell in Commvault before 14.68, 15.x before 15.58, 16.x before 16.44, 17.x before 17.29, and 18.x before 18.13, Directory Traversal can occur such that an attempt to view a log file can instead view a file outside of the log-files folder.
Conclusion & alert: CVE-2020-25780 is rated Moderate Risk (58.2/100): CVSS High severity, with high exploitation likelihood (EPSS 9.88%, 95th percentile). Core evidence: EPSS ranks this CVE among the most likely to be exploited in the near term. Mandatory action: High exploitation likelihood—assess exposure and prioritize remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 57.28% | 9.88% | -47.39% |
| 2 | 2026-05-08 | 63.36% | 57.28% | -6.09% |
| 3 | 2025-12-18 | — | 63.36% | — |
Full EPSS history (28 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.5 | 3.1 | HIGH |
|
3.9 | 3.6 | [email protected] |
| 5.0 | 2.0 | MEDIUM |
|
10.0 | 2.9 | [email protected] |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| commvault | commcell | < 14.68 | cpe:2.3:a:commvault:commcell:*:*:*:*:*:*:*:* |
| commvault | commcell | >= 15.0, < 15.58 | cpe:2.3:a:commvault:commcell:*:*:*:*:*:*:*:* |
| commvault | commcell | >= 16.0, < 16.44 | cpe:2.3:a:commvault:commcell:*:*:*:*:*:*:*:* |
| commvault | commcell | >= 17.0, < 17.29 | cpe:2.3:a:commvault:commcell:*:*:*:*:*:*:*:* |
| commvault | commcell | >= 18.0, < 18.13 | cpe:2.3:a:commvault:commcell:*:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| http://kb.commvault.com/article/63264 | Vendor Advisory |