HIGH✓ PATCH🇬🇧 English

CVE-2025-21120

CVSS 8.3v3.1pub. 2025-08-04upd. 2026-02-25

Dell Avamar, versions prior to 19.10 SP1 with patch 338904, contains a Trusting HTTP Permission Methods on the Server-Side vulnerability in Security. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.

oryginał EN
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
  • Dell Avamar

    APP
    Dell
    19.1019.1219.419.719.819.9
🟢
PATCH DOSTĘPNY
Aktualizacja od producenta gotowa. Wdrożenie w ramach standardowego cyklu.
CWE
Referencje

Powiązane podatności

CVE-2026-22769CRITICAL10.0⚠ KEVPL ✓ten sam vendor

Dell RecoverPoint for VMs — zahardkodowane dane uwierzytelniające (RCE, root)

CVE-2026-70419CRITICAL9.1ten sam vendor

Dell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements ...

CVE-2026-54489CRITICAL9.1PL ✓ten sam vendor

Dell Virtual Storage Integrator — ujawnienie sesji i przejęcie konta

CVE-2026-67261CRITICAL9.8PL ✓ten sam vendor

Dell Virtual Storage Integrator – OS Command Injection z uprawnieniami root (RCE bez uwierzytelnienia)

CVE-2026-40712CRITICAL9.1PL ✓ten sam vendor

Dell PowerProtect Data Manager – Improper Input Validation w REST API (Privilege Escalation)