CVE-2025-21117: Medium severity dell emc avamar vulnerability
Published Feb 5, 2025
·Updated
Dell Avamar, version 19.4 or later, contains an access token reuse vulnerability in the AUI. A low privileged local attacker could potentially exploit this vulnerability, leading to fully impersonating the user.
Affected Software
7 affected components
Dell Avamar>=19.4
Dell Avamar Server=19.4
Dell Avamar Server=19.7
Dell Avamar Server=19.8
Dell Avamar Server=19.9
Dell Avamar Server=19.10
Dell Avamar Server=19.10-sp1
Event History
Feb 5, 2025
CVE Published
via MITRE·01:10 PM
Data Sourced
via MITRE·01:10 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-21117?
CVE-2025-21117 is classified as a low severity vulnerability.
2
How do I fix CVE-2025-21117?
To fix CVE-2025-21117, update your Dell Avamar software to the latest available version.
3
What can an attacker do with CVE-2025-21117?
An attacker exploiting CVE-2025-21117 could potentially impersonate a user by reusing their access token.
4
Which versions of Dell Avamar are affected by CVE-2025-21117?
CVE-2025-21117 affects Dell Avamar versions 19.4 and later.
5
Who is at risk from CVE-2025-21117?
Low privileged local attackers may exploit CVE-2025-21117 if they have access to the affected Dell Avamar systems.