CVE-2025-22399

Dell UCC Edge, version 2.3.0, contains a Blind SSRF on Add Customer SFTP Server vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Server-side request forgery
Configurations

Configuration 1 (hide)

cpe:2.3:a:dell:utility_configuration_collector_edge:2.3.0:*:*:*:*:*:*:*

History

06 Dec 2025, 00:48

Type Values Removed Values Added
Summary
  • (es) Dell UCC Edge, versión 2.3.0, contiene una vulnerabilidad de SSRF ciega en el servidor SFTP de adición de clientes. Un atacante no autenticado con acceso local podría aprovechar esta vulnerabilidad, lo que provocaría Server-Side Request Forgery.
CPE cpe:2.3:a:dell:utility_configuration_collector_edge:2.3.0:*:*:*:*:*:*:*
References () https://www.dell.com/support/kbdoc/en-us/000279299/dsa-2025-043-security-update-for-dell-ucc-edge-security-update-for-multiple-vulnerabilities - () https://www.dell.com/support/kbdoc/en-us/000279299/dsa-2025-043-security-update-for-dell-ucc-edge-security-update-for-multiple-vulnerabilities - Patch, Vendor Advisory
First Time Dell
Dell utility Configuration Collector Edge

11 Feb 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-11 17:15

Updated : 2025-12-06 00:48


NVD link : CVE-2025-22399

Mitre link : CVE-2025-22399

CVE.ORG link : CVE-2025-22399


JSON object : View

Products Affected

dell

  • utility_configuration_collector_edge
CWE
CWE-918

Server-Side Request Forgery (SSRF)