Unquoted Search Path Vulnerability in Dell NetWorker
CVE-2025-21107

7.8HIGH

Key Information:

Vendor
Dell
Status
Vendor
CVE Published:
30 January 2025

Summary

Dell NetWorker versions prior to 19.11.0.3, including all versions of 19.10 and earlier, are susceptible to an Unquoted Search Path vulnerability. This flaw allows local attackers with low privileges to exploit the system, potentially leading to unauthorized code execution. Organizations using affected versions should implement recommended updates to mitigate associated risks. For further details, refer to Dell's official security advisory.

Affected Version(s)

NetWorker 19.11 <= 19.11.0.2

NetWorker 19.10 <= 19.10.0.6

NetWorker < 19.10

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.