CVE-2025-21104

MEDIUM

Dell NetWorker < 19.11.0.4 and 19.12 - Unauthenticated Open Redirect in Management Console

Title source: llm
STIX 2.1

Description

Dell NetWorker, versions prior to 19.11.0.4 and version 19.12, contains an URL Redirection to Untrusted Site ('Open Redirect') Vulnerability in NetWorker Management Console. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to a targeted application user being redirected to arbitrary web URLs. The vulnerability could be leveraged by attackers to conduct phishing attacks that cause users to divulge sensitive information.

Scores

CVSS v3 4.3
EPSS 0.0034
EPSS Percentile 56.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-601
Status published
Products (2)
dell/networker 19.12
dell/networker < 19.11.0.4
Published Mar 13, 2025
Tracked Since Feb 18, 2026