Home

Description

Dell PowerProtect Cyber Recovery, versions prior to 19.18.0.2, contains an Insertion of Sensitive Information Into Sent Data vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.

PUBLISHED Reserved 2025-02-07 | Published 2025-04-11 | Updated 2025-04-11 | Assigner dell




MEDIUM: 5.8CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N

Problem types

CWE-201: Insertion of Sensitive Information Into Sent Data

Product status

Default status
unaffected

Any version before 19.18.0.2
affected

References

www.dell.com/...-update-for-dell-powerprotect-cyber-recovery vendor-advisory

cve.org (CVE-2025-26335)

nvd.nist.gov (CVE-2025-26335)

Download JSON