CVE-2025-29986

Dell Common Event Enabler, version(s) CEE 9.0.0.0, contain(s) an Improper Restriction of Communication Channel to Intended Endpoints vulnerability in the Common Anti-Virus Agent (CAVA). An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.
Configurations

Configuration 1 (hide)

cpe:2.3:a:dell:common_event_enabler:9.0.0.0:*:*:*:*:*:*:*

History

15 Jul 2025, 16:08

Type Values Removed Values Added
First Time Dell common Event Enabler
Dell
Summary
  • (es) Dell Common Event Enabler, versión CEE 9.0.0.0, presenta una vulnerabilidad de restricción incorrecta del canal de comunicación a los endpoints previstos en el agente antivirus común (CAVA). Un atacante no autenticado con acceso remoto podría explotar esta vulnerabilidad, lo que provocaría un acceso no autorizado.
References () https://www.dell.com/support/kbdoc/en-us/000303931/dsa-2025-158-security-update-for-dell-common-event-enabler-vulnerabilities - () https://www.dell.com/support/kbdoc/en-us/000303931/dsa-2025-158-security-update-for-dell-common-event-enabler-vulnerabilities - Vendor Advisory
CPE cpe:2.3:a:dell:common_event_enabler:9.0.0.0:*:*:*:*:*:*:*

08 Apr 2025, 11:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-08 11:15

Updated : 2025-07-15 16:08


NVD link : CVE-2025-29986

Mitre link : CVE-2025-29986

CVE.ORG link : CVE-2025-29986


JSON object : View

Products Affected

dell

  • common_event_enabler
CWE
CWE-923

Improper Restriction of Communication Channel to Intended Endpoints