DSA-2025-268: Security Update for Dell NetWorker Selection of Less-Secure Algorithm During Negotiation ('Algorithm Downgrade') Vulnerability
Resumo: Dell NetWorker remediation is available for selection of less-secure algorithm during negotiation ('algorithm downgrade') vulnerability that could be exploited by malicious users to compromise the affected system. ...
Este artigo aplica-se a
Este artigo não se aplica a
Este artigo não está vinculado a nenhum produto específico.
Nem todas as versões do produto estão identificadas neste artigo.
Impacto
Medium
Dados
| Proprietary Code CVEs | Description | CVSS Base Score | CVSS Vector String |
| CVE-2025-36582 | Dell NetWorker, versions 19.12.0.1 and prior, contains a Selection of Less-Secure Algorithm During Negotiation ('Algorithm Downgrade') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure. | 4.8 | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N |
| Proprietary Code CVEs | Description | CVSS Base Score | CVSS Vector String |
| CVE-2025-36582 | Dell NetWorker, versions 19.12.0.1 and prior, contains a Selection of Less-Secure Algorithm During Negotiation ('Algorithm Downgrade') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure. | 4.8 | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N |
Produtos afetados e soluções
| Product | Software/Firmware | Affected Versions | Remediated Versions | Link |
| NetWorker | NetWorker Management Console, NetWorker Web UI, NetWorker Authentication Service | Versions prior to 19.13 | Version 19.13 or later | NetWorker Downloads Area |
| Product | Software/Firmware | Affected Versions | Remediated Versions | Link |
| NetWorker | NetWorker Management Console, NetWorker Web UI, NetWorker Authentication Service | Versions prior to 19.13 | Version 19.13 or later | NetWorker Downloads Area |
Notes:
- The Affected Products and Remediation table above may not be a comprehensive list of all affected supported versions and may be updated as more information becomes available.
- Versions prior to 19.13 means 19.12.x, 19.11.x, 19.10.x, 19.9.x, 19.8.x, 19.7.x, 19.6.x, 19.5.x, and 19.4.x family of releases that are still under standard support. For more information on Dell End-of-Life Documents for converged infrastructure, midrange and enterprise storage, and storage networking products refer to Dell End-of-Life Product List for Converged Infrastructure and Storage.
- Unless specified as impacted, the term “later releases” encompasses all NetWorker releases, under standard support, that are of a higher minor or major version than the specified release. Dell recommends that you always upgrade to the latest release/version for your product.
- Platforms: Windows & Linux (All variants and flavors are impacted).
Soluções temporárias e atenuações
None
Histórico de revisão
| Revision | Date | Description |
| 1.0 | 2025-07-01 | Initial Release |
| 2.0 | 2025-08-19 | Updated the 'Affected and Remediated Versions' and 'Additional Information' sections |
Informações relacionadas
Aviso de isenção legal
Produtos afetados
NetWorker FamilyPropriedades do artigo
Número do artigo: 000338757
Tipo de artigo: Dell Security Advisory
Último modificado: 19 ago. 2025
Encontre as respostas de outros usuários da Dell para suas perguntas.
Serviços de suporte
Verifique se o dispositivo está coberto pelos serviços de suporte.