CVE-2025-22399

D

ell UCC Edge, version 2.3.0, contains a Blind SSRF on Add Customer SFTP Server vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Server-side request forgery

Configurations

Configuration 1 (hide)

cpe:2.3:a:dell:utility_configuration_collector_edge:2.3.0:*:*:*:*:*:*:*

History

06 Dec 2025, 00:48

Type Values Removed Values Added
First Time Dell
Dell utility Configuration Collector Edge
CPE cpe:2.3:a:dell:utility_configuration_collector_edge:2.3.0:*:*:*:*:*:*:*
References () https://www.dell.com/support/kbdoc/en-us/000279299/dsa-2025-043-security-update-for-dell-ucc-edge-security-update-for-multiple-vulnerabilities - () https://www.dell.com/support/kbdoc/en-us/000279299/dsa-2025-043-security-update-for-dell-ucc-edge-security-update-for-multiple-vulnerabilities - Patch, Vendor Advisory
Summary
  • (es) Dell UCC Edge, versión 2.3.0, contiene una vulnerabilidad de SSRF ciega en el servidor SFTP de adición de clientes. Un atacante no autenticado con acceso local podría aprovechar esta vulnerabilidad, lo que provocaría Server-Side Request Forgery.

11 Feb 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-11 17:15

Updated : 2025-12-06 00:48


NVD link : CVE-2025-22399

Mitre link : CVE-2025-22399

CVE.ORG link : CVE-2025-22399


JSON object : View

CWE
CWE-918

Server-Side Request Forgery (SSRF)