CVE-2025-21117

Dell Avamar, version 19.4 or later, contains an access token reuse vulnerability in the AUI. A low privileged local attacker could potentially exploit this vulnerability, leading to fully impersonating the user.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:dell:avamar_server:19.4:*:*:*:*:*:*:*
cpe:2.3:a:dell:avamar_server:19.7:*:*:*:*:*:*:*
cpe:2.3:a:dell:avamar_server:19.8:*:*:*:*:*:*:*
cpe:2.3:a:dell:avamar_server:19.9:*:*:*:*:*:*:*
cpe:2.3:a:dell:avamar_server:19.10:-:*:*:*:*:*:*
cpe:2.3:a:dell:avamar_server:19.10:sp1:*:*:*:*:*:*

History

28 Mar 2025, 13:24

Type Values Removed Values Added
CPE cpe:2.3:a:dell:avamar_server:19.8:*:*:*:*:*:*:*
cpe:2.3:a:dell:avamar_server:19.4:*:*:*:*:*:*:*
cpe:2.3:a:dell:avamar_server:19.7:*:*:*:*:*:*:*
cpe:2.3:a:dell:avamar_server:19.9:*:*:*:*:*:*:*
cpe:2.3:a:dell:avamar_server:19.10:sp1:*:*:*:*:*:*
cpe:2.3:a:dell:avamar_server:19.10:-:*:*:*:*:*:*
First Time Dell avamar Server
Dell
Summary
  • (es) Dell Avamar, versión 19.4 o posterior, contiene una vulnerabilidad de reutilización de token de acceso en la interfaz de usuario de autenticación. Un atacante local con pocos privilegios podría aprovechar esta vulnerabilidad y suplantar por completo la identidad del usuario.
References () https://www.dell.com/support/kbdoc/en-us/000281275/dsa-2025-071-security-update-for-dell-avamar-for-multiple-component-vulnerabilities - () https://www.dell.com/support/kbdoc/en-us/000281275/dsa-2025-071-security-update-for-dell-avamar-for-multiple-component-vulnerabilities - Vendor Advisory

05 Feb 2025, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-05 14:15

Updated : 2025-03-28 13:24


NVD link : CVE-2025-21117

Mitre link : CVE-2025-21117

CVE.ORG link : CVE-2025-21117


JSON object : View

Products Affected

dell

  • avamar_server
CWE
CWE-672

Operation on a Resource after Expiration or Release