CVE Vulnerabilities

CVE-2025-21117

Operation on a Resource after Expiration or Release

Published: Feb 05, 2025 | Modified: Mar 28, 2025
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Dell Avamar, version 19.4 or later, contains an access token reuse vulnerability in the AUI. A low privileged local attacker could potentially exploit this vulnerability, leading to fully impersonating the user.

Weakness

The product uses, accesses, or otherwise operates on a resource after that resource has been expired, released, or revoked.

Affected Software

NameVendorStart VersionEnd Version
Avamar_serverDell19.4 (including)19.4 (including)
Avamar_serverDell19.7 (including)19.7 (including)
Avamar_serverDell19.8 (including)19.8 (including)
Avamar_serverDell19.9 (including)19.9 (including)
Avamar_serverDell19.10 (including)19.10 (including)
Avamar_serverDell19.10-sp1 (including)19.10-sp1 (including)

References