CVE-2025-21120
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
04/08/2025
Last modified:
25/02/2026
Description
Dell Avamar, versions prior to 19.10 SP1 with patch 338904, contains a Trusting HTTP Permission Methods on the Server-Side vulnerability in Security. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.
Impact
Base Score 3.x
8.30
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:dell:avamar:19.4:*:*:*:virtual:esxi:*:* | ||
| cpe:2.3:a:dell:avamar:19.4:*:*:*:virtual:vmware:*:* | ||
| cpe:2.3:a:dell:avamar:19.4:*:*:*:virtual:vsphere:*:* | ||
| cpe:2.3:a:dell:avamar:19.7:*:*:*:virtual:esxi:*:* | ||
| cpe:2.3:a:dell:avamar:19.7:*:*:*:virtual:vmware:*:* | ||
| cpe:2.3:a:dell:avamar:19.7:*:*:*:virtual:vsphere:*:* | ||
| cpe:2.3:a:dell:avamar:19.8:*:*:*:virtual:esxi:*:* | ||
| cpe:2.3:a:dell:avamar:19.8:*:*:*:virtual:vmware:*:* | ||
| cpe:2.3:a:dell:avamar:19.8:*:*:*:virtual:vsphere:*:* | ||
| cpe:2.3:a:dell:avamar:19.9:*:*:*:virtual:esxi:*:* | ||
| cpe:2.3:a:dell:avamar:19.9:*:*:*:virtual:vmware:*:* | ||
| cpe:2.3:a:dell:avamar:19.9:*:*:*:virtual:vsphere:*:* | ||
| cpe:2.3:a:dell:avamar:19.10:-:*:*:virtual:esxi:*:* | ||
| cpe:2.3:a:dell:avamar:19.10:-:*:*:virtual:vmware:*:* | ||
| cpe:2.3:a:dell:avamar:19.10:-:*:*:virtual:vsphere:*:* |
To consult the complete list of CPE names with products and versions, see this page



