Dell UCC Edge, version 2.3.0, contains a Blind SSRF on Add Customer SFTP Server vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Server-side request forgery
References
| Link | Resource |
|---|---|
| https://www.dell.com/support/kbdoc/en-us/000279299/dsa-2025-043-security-update-for-dell-ucc-edge-security-update-for-multiple-vulnerabilities | Patch Vendor Advisory |
Configurations
History
06 Dec 2025, 00:48
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
|
| CPE | cpe:2.3:a:dell:utility_configuration_collector_edge:2.3.0:*:*:*:*:*:*:* | |
| References | () https://www.dell.com/support/kbdoc/en-us/000279299/dsa-2025-043-security-update-for-dell-ucc-edge-security-update-for-multiple-vulnerabilities - Patch, Vendor Advisory | |
| First Time |
Dell
Dell utility Configuration Collector Edge |
11 Feb 2025, 17:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-02-11 17:15
Updated : 2025-12-06 00:48
NVD link : CVE-2025-22399
Mitre link : CVE-2025-22399
CVE.ORG link : CVE-2025-22399
JSON object : View
Products Affected
dell
- utility_configuration_collector_edge
CWE
CWE-918
Server-Side Request Forgery (SSRF)
