CVE-2025-21120

HIGH

Dell Avamar <19.12-19.10SP1 - Info Disclosure

Title source: llm
STIX 2.1

Description

Dell Avamar, versions prior to 19.10 SP1 with patch 338904, contains a Trusting HTTP Permission Methods on the Server-Side vulnerability in Security. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.

Scores

CVSS v3 8.3
EPSS 0.0009
EPSS Percentile 25.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-650
Status published
Products (6)
dell/avamar 19.4 (3 CPE variants)
dell/avamar 19.7 (3 CPE variants)
dell/avamar 19.8 (3 CPE variants)
dell/avamar 19.9 (3 CPE variants)
dell/avamar 19.10 (6 CPE variants)
dell/avamar 19.12 (3 CPE variants)
Published Aug 04, 2025
Tracked Since Feb 18, 2026