# CVE-2025-21117

## Summary

- **CVE ID:** CVE-2025-21117
- **Severity:** MEDIUM
- **CVSS Score:** 6.6 (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N)
- **CWE:** CWE-672
- **Published:** Feb 5, 2025
- **Last Modified:** Mar 12, 2026

## Description

Dell Avamar, version 19.4 or later, contains an access token reuse vulnerability in the AUI. A low privileged local attacker could potentially exploit this vulnerability, leading to fully impersonating the user.

## Affected Products

- Dell — Avamar (19.4)
- Dell — Avamar (19.7)
- Dell — Avamar (19.8)
- Dell — Avamar (19.9)
- Dell — Avamar (19.10)
- Dell — Avamar (19.10 SP1)

## References

- [CNA](https://www.dell.com/support/kbdoc/en-us/000281275/dsa-2025-071-security-update-for-dell-avamar-for-multiple-component-vulnerabilities)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.16%
- **EPSS Percentile:** 5.6

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._