CVE-2025-26335

Dell PowerProtect Cyber Recovery, versions prior to 19.18.0.2, contains an Insertion of Sensitive Information Into Sent Data vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.
Configurations

Configuration 1 (hide)

cpe:2.3:a:dell:powerprotect_cyber_recovery:*:*:*:*:*:*:*:*

History

14 Jan 2026, 14:33

Type Values Removed Values Added
First Time Dell
Dell powerprotect Cyber Recovery
CWE NVD-CWE-noinfo
CPE cpe:2.3:a:dell:powerprotect_cyber_recovery:*:*:*:*:*:*:*:*
References () https://www.dell.com/support/kbdoc/en-us/000306005/dsa-2025-113-security-update-for-dell-powerprotect-cyber-recovery - () https://www.dell.com/support/kbdoc/en-us/000306005/dsa-2025-113-security-update-for-dell-powerprotect-cyber-recovery - Vendor Advisory

11 Apr 2025, 15:39

Type Values Removed Values Added
Summary
  • (es) Dell PowerProtect Cyber Recovery, versiones anteriores a 19.18.0.2, contiene una vulnerabilidad de inserción de información confidencial en los datos enviados. Un atacante con altos privilegios y acceso remoto podría potencialmente explotar esta vulnerabilidad, provocando la exposición de la información.

11 Apr 2025, 02:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-11 02:15

Updated : 2026-01-14 14:33


NVD link : CVE-2025-26335

Mitre link : CVE-2025-26335

CVE.ORG link : CVE-2025-26335


JSON object : View

Products Affected

dell

  • powerprotect_cyber_recovery
CWE
CWE-201

Insertion of Sensitive Information Into Sent Data

NVD-CWE-noinfo