CVE 8.3 HIGH

CVE-2025-21120_CVE-2025-21120

8.3 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L

Description

Dell Avamar, versions prior to 19.12 with patch 338905, excluding version 19.10SP1 with patch 338904, contains a Trusting HTTP Permission Methods on the Server-Side vulnerability in Security. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.

Basic Information

ID CVE-2025-21120
Source dell
Published Aug 4, 2025 at 18:33
Modified Aug 7, 2025 at 03:55

Affected Product

Vendor Dell
Product Avamar Data Store Gen4T
Version 19.12
Affected Versions Dell Avamar Data Store Gen4T 19.12
Dell Avamar Data Store Gen4T 19.10, 19.10-SP1, 19.7, 19.8, 19.9 and 19.4
Dell Avamar Data Store Gen5A 19.12
Dell Avamar Data Store Gen5A 19.10, 19.10-SP1, 19.7, 19.8, 19.9 and 19.4
Dell Avamar Virtual Edition for VMware ESXi and vSphere 19.12
Dell Avamar Virtual Edition for VMware ESXi and vSphere 19.10, 19.10-SP1, 19.7, 19.8, 19.9 and 19.4
Dell Avamar Virtual Edition for VMware vSphere only 19.12
Dell Avamar Virtual Edition for VMware vSphere only 19.10, 19.10-SP1, 19.7, 19.8, 19.9 and 19.4

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.