CVE-2025-36597: Dell Avamar Server

Medium severity, CVSS 4.7. EPSS: 0.3% chance of exploitation in the next 30 days.

Dell Avamar, versions prior to 19.12 with patch 338905, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in the Security. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to information disclosure.

Affected products

  • Dell Avamar Server
  • Dell Avamar Virtual Edition
  • Dell Powerprotect Dp Series Appliance Idpa

Published 2026-02-17. Last modified 2026-06-17.