6.5
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
Description
Dell Avamar, versions prior to 19.12 with patch 338905, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in the Security. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to upload malicious files.
Basic Information
ID
CVE-2025-36598
Source
dell
Published
Feb 17, 2026 at 19:27
Modified
Feb 17, 2026 at 21:00
Affected Product
Vendor
Dell
Product
Avamar Virtual Edition
Version
19.8 through 19.12
Affected Versions
Dell Avamar Virtual Edition 19.8 through 19.12
Dell PowerProtect DP Series Appliance (IDPA) N/A
Dell PowerProtect DP Series Appliance (IDPA) N/A