CVE-2025-21120

EUVD-2025-23530
Dell Avamar, versions prior to 19.10 SP1 with patch 338904, contains a Trusting HTTP Permission Methods on the Server-Side vulnerability in Security. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.3 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
dellavamar
19.4
dellavamar
19.4
dellavamar
19.4
dellavamar
19.7
dellavamar
19.7
dellavamar
19.7
dellavamar
19.8
dellavamar
19.8
dellavamar
19.8
dellavamar
19.9
dellavamar
19.9
dellavamar
19.9
dellavamar
19.10
dellavamar
19.10
dellavamar
19.10
dellavamar
19.10:sp1
dellavamar
19.10:sp1
dellavamar
19.10:sp1
dellavamar
19.12
dellavamar
19.12
dellavamar
19.12
𝑥
= Vulnerable software versions