CVE-2025-29986HIGH 8.3EPSS p14.0%

CVE-2025-29986CVE-2025-29986

Description

Dell Common Event Enabler, version(s) CEE 9.0.0.0, contain(s) an Improper Restriction of Communication Channel to Intended Endpoints vulnerability in the Common Anti-Virus Agent (CAVA). An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.

Scoring

CVSS 3.18.3 (HIGH)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L
EPSS0.23% probability of exploitation · percentile 14.0% · 2026-06-18T12:00:27Z
Published2025-04-08
Last modified2025-07-15

Underlying weaknesses· 1

CWE-923

References

  1. https://www.dell.com/support/kbdoc/en-us/000303931/dsa-2025-158-security-update-for-dell-common-event-enabler-vulnerabilities

1

TypeTargetConfidenceTier
WeaknessImproper Restriction of Communication Channel to Intended Endpointscwe-9230%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2026-32658
CVE
CVE-2025-29987
CVE
CVE-2025-24919
CVE
CVE-2026-28264
CVE
CVE-2025-32089
CVE
CVE-2025-26477
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.