CVE-2025-46699 Details
Description
Dell Data Protection Advisor, versions prior to 19.12, contains an Improper Neutralization of Special Elements Used in a Template Engine vulnerability in the Server. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.
A vulnerability exists in Dell Data Protection Advisor (DPA) versions prior to 19.12, related to improper neutralization of special elements used in a template engine within the server component. This vulnerability allows a low-privileged attacker with remote access to potentially exploit the issue, leading to information exposure.
Users can upgrade to Dell Data Protection Advisor version 19.12 or later. For versions 19.11 and later, a script is available to remove affected OpenSSL 1.0.2 dependent libraries. This script can be obtained from Dell Customer Support.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jan 23, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-1336 | Improper Neutralization of Special Elements Used in a Template Engine | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| dell data protection advisor | >= 19.9, < 19.12 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 28, 2026 | Initial Analysis | [email protected] |
| Jan 23, 2026 | New CVE Received | [email protected] |