Description
Dell Avamar, versions prior to 19.10 SP1 with patch 338904, contains a Trusting HTTP Permission Methods on the Server-Side vulnerability in Security. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.
Published: 2025-08-04
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-23530 Dell Avamar, versions prior to 19.12 with patch 338905, excluding version 19.10SP1 with patch 338904, contains a Trusting HTTP Permission Methods on the Server-Side vulnerability in Security. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.
History

Wed, 25 Feb 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Dell avamar
CPEs cpe:2.3:a:dell:avamar:19.10:-:*:*:virtual:esxi:*:*
cpe:2.3:a:dell:avamar:19.10:-:*:*:virtual:vmware:*:*
cpe:2.3:a:dell:avamar:19.10:-:*:*:virtual:vsphere:*:*
cpe:2.3:a:dell:avamar:19.10:sp1:*:*:virtual:esxi:*:*
cpe:2.3:a:dell:avamar:19.10:sp1:*:*:virtual:vmware:*:*
cpe:2.3:a:dell:avamar:19.10:sp1:*:*:virtual:vsphere:*:*
cpe:2.3:a:dell:avamar:19.12:*:*:*:virtual:esxi:*:*
cpe:2.3:a:dell:avamar:19.12:*:*:*:virtual:vmware:*:*
cpe:2.3:a:dell:avamar:19.12:*:*:*:virtual:vsphere:*:*
cpe:2.3:a:dell:avamar:19.4:*:*:*:virtual:esxi:*:*
cpe:2.3:a:dell:avamar:19.4:*:*:*:virtual:vmware:*:*
cpe:2.3:a:dell:avamar:19.4:*:*:*:virtual:vsphere:*:*
cpe:2.3:a:dell:avamar:19.7:*:*:*:virtual:esxi:*:*
cpe:2.3:a:dell:avamar:19.7:*:*:*:virtual:vmware:*:*
cpe:2.3:a:dell:avamar:19.7:*:*:*:virtual:vsphere:*:*
cpe:2.3:a:dell:avamar:19.8:*:*:*:virtual:esxi:*:*
cpe:2.3:a:dell:avamar:19.8:*:*:*:virtual:vmware:*:*
cpe:2.3:a:dell:avamar:19.8:*:*:*:virtual:vsphere:*:*
cpe:2.3:a:dell:avamar:19.9:*:*:*:virtual:esxi:*:*
cpe:2.3:a:dell:avamar:19.9:*:*:*:virtual:vmware:*:*
cpe:2.3:a:dell:avamar:19.9:*:*:*:virtual:vsphere:*:*
Vendors & Products Dell avamar

Tue, 17 Feb 2026 19:15:00 +0000

Type Values Removed Values Added
Description Dell Avamar, versions prior to 19.12 with patch 338905, excluding version 19.10SP1 with patch 338904, contains a Trusting HTTP Permission Methods on the Server-Side vulnerability in Security. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure. Dell Avamar, versions prior to 19.10 SP1 with patch 338904, contains a Trusting HTTP Permission Methods on the Server-Side vulnerability in Security. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.

Tue, 05 Aug 2025 11:45:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell avamar Data Store
Dell avamar Server
Vendors & Products Dell
Dell avamar Data Store
Dell avamar Server

Mon, 04 Aug 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 04 Aug 2025 18:45:00 +0000

Type Values Removed Values Added
Description Dell Avamar, versions prior to 19.12 with patch 338905, excluding version 19.10SP1 with patch 338904, contains a Trusting HTTP Permission Methods on the Server-Side vulnerability in Security. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.
Weaknesses CWE-650
References
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L'}


Subscriptions

Dell Avamar Avamar Data Store Avamar Server
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-02-26T17:49:58.914Z

Reserved: 2024-11-23T06:04:00.843Z

Link: CVE-2025-21120

cve-icon Vulnrichment

Updated: 2025-08-04T19:16:53.698Z

cve-icon NVD

Status : Analyzed

Published: 2025-08-04T19:15:30.210

Modified: 2026-02-25T15:14:51.750

Link: CVE-2025-21120

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-08-05T11:38:54Z

Weaknesses