CVE-2025-21117: Dell Avamar Server

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

Dell Avamar, version 19.4 or later, contains an access token reuse vulnerability in the AUI. A low privileged local attacker could potentially exploit this vulnerability, leading to fully impersonating the user.

Affected products

  • Dell Avamar Server: version 19.4 only; version 19.7 only; version 19.8 only; version 19.9 only; version 19.10 only

Published 2025-02-05. Last modified 2026-06-17.