CVE-2025-21103 Details
Description
Dell NetWorker Management Console, version(s) 19.11 through 19.11.0.3 & Versions prior to 19.10.0.7 contain(s) an improper neutralization of server-side vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability and run arbitrary code on the server.
A vulnerability allowing arbitrary code execution has been identified in Dell NetWorker Management Console versions 19.11 through 19.11.0.3 and versions prior to 19.10.0.7. This vulnerability arises from improper neutralization of server-side input, which could be exploited by an unauthenticated attacker with local access to execute arbitrary code on the server.
Users can upgrade to version 19.11.0.4 or later. For versions prior to 19.10.0.7, version 19.10.0.7 or 19.11.0.4 can be installed. The latest versions can be downloaded from the Dell Support website.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 18, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.dell.com/support/kbdoc/en-us/000286268/dsa-2025-095-security-update-for-dell-networker-management-console-vulnerability | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-97 | Improper Neutralization of Server-Side Includes (SSI) Within a Web Page | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| dell networker | < 19.10.0.7 >= 19.11, <= 19.11.0.3 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Dec 6, 2025 | Initial Analysis | [email protected] |
| Feb 17, 2025 | New CVE Received | [email protected] |