CVE-2025-21106

Dell Recover Point for Virtual Machines 6.0.X contains a Weak file system permission vulnerability. A low privileged Local attacker could potentially exploit this vulnerability, leading to impacting only non-sensitive resources in the system.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:dell:recoverpoint_for_virtual_machines:6.0:sp1:*:*:*:*:*:*
cpe:2.3:a:dell:recoverpoint_for_virtual_machines:6.0:sp1_p1:*:*:*:*:*:*
cpe:2.3:a:dell:recoverpoint_for_virtual_machines:6.0:sp1_p2:*:*:*:*:*:*

History

31 Jul 2025, 17:32

Type Values Removed Values Added
References () https://www.dell.com/support/kbdoc/en-us/000287503/dsa-2025-101-security-update-for-dell-recoverpoint-for-virtual-machines-multiple-component-vulnerabilities - () https://www.dell.com/support/kbdoc/en-us/000287503/dsa-2025-101-security-update-for-dell-recoverpoint-for-virtual-machines-multiple-component-vulnerabilities - Vendor Advisory
First Time Dell
Dell recoverpoint For Virtual Machines
Summary
  • (es) Dell Recover Point for Virtual Machines 6.0.X contiene una vulnerabilidad de permisos débiles en el sistema de archivos. Un atacante local con pocos privilegios podría aprovechar esta vulnerabilidad, lo que afectaría únicamente a los recursos no confidenciales del sistema.
CPE cpe:2.3:a:dell:recoverpoint_for_virtual_machines:6.0:sp1_p1:*:*:*:*:*:*
cpe:2.3:a:dell:recoverpoint_for_virtual_machines:6.0:sp1:*:*:*:*:*:*
cpe:2.3:a:dell:recoverpoint_for_virtual_machines:6.0:sp1_p2:*:*:*:*:*:*

20 Feb 2025, 12:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-20 12:15

Updated : 2025-07-31 17:32


NVD link : CVE-2025-21106

Mitre link : CVE-2025-21106

CVE.ORG link : CVE-2025-21106


JSON object : View

Products Affected

dell

  • recoverpoint_for_virtual_machines
CWE
CWE-276

Incorrect Default Permissions