Dell Avamar Server vulnerabilities
7 known vulnerabilities affecting dell/avamar_server.
Total CVEs
7
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH2MEDIUM4
Vulnerabilities
Page 1 of 1
CVE-2026-22762MEDIUMCVSS 6.5≥ 19.9 through 19.10 SP1, < 19.10 SP1 with CHF 338912 or later2026-02-17
CVE-2026-22762 [MEDIUM] CWE-22 CVE-2026-22762: Dell Avamar Server and Avamar Virtual Edition, versions prior to 19.10 SP1 with CHF338912, contain a
Dell Avamar Server and Avamar Virtual Edition, versions prior to 19.10 SP1 with CHF338912, contain an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in the Security. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to arbitrary file delete.
cvelistv5nvd
CVE-2025-36597MEDIUMCVSS 4.7≥ 19.8 through 19.12, < Version 19.12 with CHF 338905 or later2026-02-17
CVE-2025-36597 [MEDIUM] CWE-22 CVE-2025-36597: Dell Avamar, versions prior to 19.12 with patch 338905, contains an Improper Limitation of a Pathnam
Dell Avamar, versions prior to 19.12 with patch 338905, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in the Security. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to information disclosure.
cvelistv5nvd
CVE-2025-21120MEDIUMCVSS 6.5≥ 19.8 through 19.10, < 19.10 SP1 with CHF 338904 or later2025-08-04
CVE-2025-21120 [MEDIUM] CWE-650 CVE-2025-21120: Dell Avamar, versions prior to 19.10 SP1 with patch 338904, contains a Trusting HTTP Permission Meth
Dell Avamar, versions prior to 19.10 SP1 with patch 338904, contains a Trusting HTTP Permission Methods on the Server-Side vulnerability in Security. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.
cvelistv5nvd
CVE-2025-21117MEDIUMCVSS 5.5v19.4v19.7+3 more2025-02-05
CVE-2025-21117 [MEDIUM] CWE-672 CVE-2025-21117: Dell Avamar, version 19.4 or later, contains an access token reuse vulnerability in the AUI. A low p
Dell Avamar, version 19.4 or later, contains an access token reuse vulnerability in the AUI. A low privileged local attacker could potentially exploit this vulnerability, leading to fully impersonating the user.
nvd
CVE-2024-47484CRITICALCVSS 9.8v19.4v19.7+3 more2024-12-10
CVE-2024-47484 [CRITICAL] CWE-89 CVE-2024-47484: Dell Avamar, versions prior to 19.12 with patch 338905, excluding 19.10 and 19.10SP1 with patch 3388
Dell Avamar, versions prior to 19.12 with patch 338905, excluding 19.10 and 19.10SP1 with patch 338869, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Command execution.
nvd
CVE-2024-52538HIGHCVSS 8.8v19.4v19.7+3 more2024-12-10
CVE-2024-52538 [HIGH] CWE-89 CVE-2024-52538: Dell Avamar, versions prior to 19.12 with patch 338905, excluding 19.10 and 19.10SP1 with patch 3388
Dell Avamar, versions prior to 19.12 with patch 338905, excluding 19.10 and 19.10SP1 with patch 338869, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Script injection.
nvd
CVE-2024-47977HIGHCVSS 8.8v19.4v19.7+3 more2024-12-10
CVE-2024-47977 [HIGH] CWE-89 CVE-2024-47977: Dell Avamar, versions prior to 19.12 with patch 338905, excluding 19.10 and 19.10SP1 with patch 3388
Dell Avamar, versions prior to 19.12 with patch 338905, excluding 19.10 and 19.10SP1 with patch 338869, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution.
nvd