8.3
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
Description
Dell Avamar, versions prior to 19.12 with patch 338905, excluding version 19.10SP1 with patch 338904, contains a Trusting HTTP Permission Methods on the Server-Side vulnerability in Security. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.
Basic Information
ID
CVE-2025-21120
Source
dell
Published
Aug 4, 2025 at 18:33
Modified
Aug 7, 2025 at 03:55
Affected Product
Vendor
Dell
Product
Avamar Data Store Gen4T
Version
19.12
Affected Versions
Dell Avamar Data Store Gen4T 19.12
Dell Avamar Data Store Gen4T 19.10, 19.10-SP1, 19.7, 19.8, 19.9 and 19.4
Dell Avamar Data Store Gen5A 19.12
Dell Avamar Data Store Gen5A 19.10, 19.10-SP1, 19.7, 19.8, 19.9 and 19.4
Dell Avamar Virtual Edition for VMware ESXi and vSphere 19.12
Dell Avamar Virtual Edition for VMware ESXi and vSphere 19.10, 19.10-SP1, 19.7, 19.8, 19.9 and 19.4
Dell Avamar Virtual Edition for VMware vSphere only 19.12
Dell Avamar Virtual Edition for VMware vSphere only 19.10, 19.10-SP1, 19.7, 19.8, 19.9 and 19.4
Dell Avamar Data Store Gen4T 19.10, 19.10-SP1, 19.7, 19.8, 19.9 and 19.4
Dell Avamar Data Store Gen5A 19.12
Dell Avamar Data Store Gen5A 19.10, 19.10-SP1, 19.7, 19.8, 19.9 and 19.4
Dell Avamar Virtual Edition for VMware ESXi and vSphere 19.12
Dell Avamar Virtual Edition for VMware ESXi and vSphere 19.10, 19.10-SP1, 19.7, 19.8, 19.9 and 19.4
Dell Avamar Virtual Edition for VMware vSphere only 19.12
Dell Avamar Virtual Edition for VMware vSphere only 19.10, 19.10-SP1, 19.7, 19.8, 19.9 and 19.4