CVE-2025-21120

Dell Avamar, versions prior to 19.10 SP1 with patch 338904, contains a Trusting HTTP Permission Methods on the Server-Side vulnerability in Security. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:dell:avamar:19.4:*:*:*:virtual:esxi:*:*
cpe:2.3:a:dell:avamar:19.4:*:*:*:virtual:vmware:*:*
cpe:2.3:a:dell:avamar:19.4:*:*:*:virtual:vsphere:*:*
cpe:2.3:a:dell:avamar:19.7:*:*:*:virtual:esxi:*:*
cpe:2.3:a:dell:avamar:19.7:*:*:*:virtual:vmware:*:*
cpe:2.3:a:dell:avamar:19.7:*:*:*:virtual:vsphere:*:*
cpe:2.3:a:dell:avamar:19.8:*:*:*:virtual:esxi:*:*
cpe:2.3:a:dell:avamar:19.8:*:*:*:virtual:vmware:*:*
cpe:2.3:a:dell:avamar:19.8:*:*:*:virtual:vsphere:*:*
cpe:2.3:a:dell:avamar:19.9:*:*:*:virtual:esxi:*:*
cpe:2.3:a:dell:avamar:19.9:*:*:*:virtual:vmware:*:*
cpe:2.3:a:dell:avamar:19.9:*:*:*:virtual:vsphere:*:*
cpe:2.3:a:dell:avamar:19.10:-:*:*:virtual:esxi:*:*
cpe:2.3:a:dell:avamar:19.10:-:*:*:virtual:vmware:*:*
cpe:2.3:a:dell:avamar:19.10:-:*:*:virtual:vsphere:*:*
cpe:2.3:a:dell:avamar:19.10:sp1:*:*:virtual:esxi:*:*
cpe:2.3:a:dell:avamar:19.10:sp1:*:*:virtual:vmware:*:*
cpe:2.3:a:dell:avamar:19.10:sp1:*:*:virtual:vsphere:*:*
cpe:2.3:a:dell:avamar:19.12:*:*:*:virtual:esxi:*:*
cpe:2.3:a:dell:avamar:19.12:*:*:*:virtual:vmware:*:*
cpe:2.3:a:dell:avamar:19.12:*:*:*:virtual:vsphere:*:*

History

25 Feb 2026, 15:14

Type Values Removed Values Added
References () https://www.dell.com/support/kbdoc/en-us/000347698/dsa-2025-271-security-update-for-dell-avamar-and-dell-avamar-virtual-edition-multiple-vulnerabilities - () https://www.dell.com/support/kbdoc/en-us/000347698/dsa-2025-271-security-update-for-dell-avamar-and-dell-avamar-virtual-edition-multiple-vulnerabilities - Vendor Advisory
CPE cpe:2.3:a:dell:avamar:19.9:*:*:*:virtual:vsphere:*:*
cpe:2.3:a:dell:avamar:19.8:*:*:*:virtual:esxi:*:*
cpe:2.3:a:dell:avamar:19.10:-:*:*:virtual:vsphere:*:*
cpe:2.3:a:dell:avamar:19.10:-:*:*:virtual:esxi:*:*
cpe:2.3:a:dell:avamar:19.8:*:*:*:virtual:vmware:*:*
cpe:2.3:a:dell:avamar:19.8:*:*:*:virtual:vsphere:*:*
cpe:2.3:a:dell:avamar:19.10:-:*:*:virtual:vmware:*:*
cpe:2.3:a:dell:avamar:19.4:*:*:*:virtual:esxi:*:*
cpe:2.3:a:dell:avamar:19.7:*:*:*:virtual:esxi:*:*
cpe:2.3:a:dell:avamar:19.10:sp1:*:*:virtual:esxi:*:*
cpe:2.3:a:dell:avamar:19.4:*:*:*:virtual:vmware:*:*
cpe:2.3:a:dell:avamar:19.9:*:*:*:virtual:esxi:*:*
cpe:2.3:a:dell:avamar:19.4:*:*:*:virtual:vsphere:*:*
cpe:2.3:a:dell:avamar:19.12:*:*:*:virtual:vmware:*:*
cpe:2.3:a:dell:avamar:19.9:*:*:*:virtual:vmware:*:*
cpe:2.3:a:dell:avamar:19.12:*:*:*:virtual:vsphere:*:*
cpe:2.3:a:dell:avamar:19.10:sp1:*:*:virtual:vsphere:*:*
cpe:2.3:a:dell:avamar:19.12:*:*:*:virtual:esxi:*:*
cpe:2.3:a:dell:avamar:19.10:sp1:*:*:virtual:vmware:*:*
cpe:2.3:a:dell:avamar:19.7:*:*:*:virtual:vsphere:*:*
cpe:2.3:a:dell:avamar:19.7:*:*:*:virtual:vmware:*:*
First Time Dell avamar
Dell

17 Feb 2026, 19:21

Type Values Removed Values Added
Summary (en) Dell Avamar, versions prior to 19.12 with patch 338905, excluding version 19.10SP1 with patch 338904, contains a Trusting HTTP Permission Methods on the Server-Side vulnerability in Security. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure. (en) Dell Avamar, versions prior to 19.10 SP1 with patch 338904, contains a Trusting HTTP Permission Methods on the Server-Side vulnerability in Security. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.

05 Aug 2025, 14:34

Type Values Removed Values Added
Summary
  • (es) Dell Avamar, versiones anteriores a la 19.12 con el parche 338905, excepto la versión 19.10SP1 con el parche 338904, contiene una vulnerabilidad de seguridad relacionada con los métodos de permisos HTTP de confianza en el servidor. Un atacante con pocos privilegios y acceso remoto podría explotar esta vulnerabilidad, lo que provocaría la exposición de información.

04 Aug 2025, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-04 19:15

Updated : 2026-02-25 15:14


NVD link : CVE-2025-21120

Mitre link : CVE-2025-21120

CVE.ORG link : CVE-2025-21120


JSON object : View

Products Affected

dell

  • avamar
CWE
CWE-650

Trusting HTTP Permission Methods on the Server Side