CVE-2025-21120

D

ell Avamar, versions prior to 19.10 SP1 with patch 338904, contains a Trusting HTTP Permission Methods on the Server-Side vulnerability in Security. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:dell:avamar:19.4:*:*:*:virtual:esxi:*:*
cpe:2.3:a:dell:avamar:19.4:*:*:*:virtual:vmware:*:*
cpe:2.3:a:dell:avamar:19.4:*:*:*:virtual:vsphere:*:*
cpe:2.3:a:dell:avamar:19.7:*:*:*:virtual:esxi:*:*
cpe:2.3:a:dell:avamar:19.7:*:*:*:virtual:vmware:*:*
cpe:2.3:a:dell:avamar:19.7:*:*:*:virtual:vsphere:*:*
cpe:2.3:a:dell:avamar:19.8:*:*:*:virtual:esxi:*:*
cpe:2.3:a:dell:avamar:19.8:*:*:*:virtual:vmware:*:*
cpe:2.3:a:dell:avamar:19.8:*:*:*:virtual:vsphere:*:*
cpe:2.3:a:dell:avamar:19.9:*:*:*:virtual:esxi:*:*
cpe:2.3:a:dell:avamar:19.9:*:*:*:virtual:vmware:*:*
cpe:2.3:a:dell:avamar:19.9:*:*:*:virtual:vsphere:*:*
cpe:2.3:a:dell:avamar:19.10:-:*:*:virtual:esxi:*:*
cpe:2.3:a:dell:avamar:19.10:-:*:*:virtual:vmware:*:*
cpe:2.3:a:dell:avamar:19.10:-:*:*:virtual:vsphere:*:*
cpe:2.3:a:dell:avamar:19.10:sp1:*:*:virtual:esxi:*:*
cpe:2.3:a:dell:avamar:19.10:sp1:*:*:virtual:vmware:*:*
cpe:2.3:a:dell:avamar:19.10:sp1:*:*:virtual:vsphere:*:*
cpe:2.3:a:dell:avamar:19.12:*:*:*:virtual:esxi:*:*
cpe:2.3:a:dell:avamar:19.12:*:*:*:virtual:vmware:*:*
cpe:2.3:a:dell:avamar:19.12:*:*:*:virtual:vsphere:*:*

History

25 Feb 2026, 15:14

Type Values Removed Values Added
References () https://www.dell.com/support/kbdoc/en-us/000347698/dsa-2025-271-security-update-for-dell-avamar-and-dell-avamar-virtual-edition-multiple-vulnerabilities - () https://www.dell.com/support/kbdoc/en-us/000347698/dsa-2025-271-security-update-for-dell-avamar-and-dell-avamar-virtual-edition-multiple-vulnerabilities - Vendor Advisory
First Time Dell avamar
Dell
CPE cpe:2.3:a:dell:avamar:19.8:*:*:*:virtual:vsphere:*:*
cpe:2.3:a:dell:avamar:19.8:*:*:*:virtual:vmware:*:*
cpe:2.3:a:dell:avamar:19.9:*:*:*:virtual:vsphere:*:*
cpe:2.3:a:dell:avamar:19.7:*:*:*:virtual:vmware:*:*
cpe:2.3:a:dell:avamar:19.12:*:*:*:virtual:esxi:*:*
cpe:2.3:a:dell:avamar:19.10:sp1:*:*:virtual:vsphere:*:*
cpe:2.3:a:dell:avamar:19.12:*:*:*:virtual:vmware:*:*
cpe:2.3:a:dell:avamar:19.10:sp1:*:*:virtual:esxi:*:*
cpe:2.3:a:dell:avamar:19.9:*:*:*:virtual:vmware:*:*
cpe:2.3:a:dell:avamar:19.4:*:*:*:virtual:esxi:*:*
cpe:2.3:a:dell:avamar:19.7:*:*:*:virtual:vsphere:*:*
cpe:2.3:a:dell:avamar:19.10:-:*:*:virtual:esxi:*:*
cpe:2.3:a:dell:avamar:19.12:*:*:*:virtual:vsphere:*:*
cpe:2.3:a:dell:avamar:19.10:-:*:*:virtual:vmware:*:*
cpe:2.3:a:dell:avamar:19.10:sp1:*:*:virtual:vmware:*:*
cpe:2.3:a:dell:avamar:19.7:*:*:*:virtual:esxi:*:*
cpe:2.3:a:dell:avamar:19.4:*:*:*:virtual:vsphere:*:*
cpe:2.3:a:dell:avamar:19.10:-:*:*:virtual:vsphere:*:*
cpe:2.3:a:dell:avamar:19.4:*:*:*:virtual:vmware:*:*
cpe:2.3:a:dell:avamar:19.8:*:*:*:virtual:esxi:*:*
cpe:2.3:a:dell:avamar:19.9:*:*:*:virtual:esxi:*:*

17 Feb 2026, 19:21

Type Values Removed Values Added
Summary (en) Dell Avamar, versions prior to 19.12 with patch 338905, excluding version 19.10SP1 with patch 338904, contains a Trusting HTTP Permission Methods on the Server-Side vulnerability in Security. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure. (en) Dell Avamar, versions prior to 19.10 SP1 with patch 338904, contains a Trusting HTTP Permission Methods on the Server-Side vulnerability in Security. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.

05 Aug 2025, 14:34

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-04 19:15

Updated : 2026-02-25 15:14


NVD link : CVE-2025-21120

Mitre link : CVE-2025-21120

CVE.ORG link : CVE-2025-21120


JSON object : View

Products Affected
CWE
CWE-650

Trusting HTTP Permission Methods on the Server Side