CVE-2025-46699

Dell Data Protection Advisor, versions prior to 19.12, contains an Improper Neutralization of Special Elements Used in a Template Engine vulnerability in the Server. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.
Configurations

Configuration 1 (hide)

cpe:2.3:a:dell:data_protection_advisor:*:*:*:*:*:*:*:*

History

17 Jun 2026, 09:26

Type Values Removed Values Added
Summary
  • (es) Dell Data Protection Advisor, versiones anteriores a la 19.12, contiene una vulnerabilidad de neutralización incorrecta de elementos especiales utilizados en un motor de plantillas en el servidor. Un atacante en remoto con pocos privilegios podría, potencialmente, explotar esta vulnerabilidad, lo que podría llevar a la exposición de información.

28 Jan 2026, 18:59

Type Values Removed Values Added
First Time Dell
Dell data Protection Advisor
CPE cpe:2.3:a:dell:data_protection_advisor:*:*:*:*:*:*:*:*
References () https://www.dell.com/support/kbdoc/en-us/000281732/dsa-2025-075-security-update-for-dell-data-protection-advisor-for-multiple-component-vulnerabilities - () https://www.dell.com/support/kbdoc/en-us/000281732/dsa-2025-075-security-update-for-dell-data-protection-advisor-for-multiple-component-vulnerabilities - Vendor Advisory

23 Jan 2026, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-23 10:15

Updated : 2026-06-17 09:26


NVD link : CVE-2025-46699

Mitre link : CVE-2025-46699

CVE.ORG link : CVE-2025-46699


JSON object : View

Products Affected

dell

  • data_protection_advisor
CWE
CWE-1336

Improper Neutralization of Special Elements Used in a Template Engine