DSA-2025-268: Security Update for Dell NetWorker Selection of Less-Secure Algorithm During Negotiation ('Algorithm Downgrade') Vulnerability

Zhrnutie: Dell NetWorker remediation is available for selection of less-secure algorithm during negotiation ('algorithm downgrade') vulnerability that could be exploited by malicious users to compromise the affected system. ...

Tento článok sa vzťahuje na Tento článok sa nevzťahuje na Tento článok nie je viazaný na žiadny konkrétny produkt. V tomto článku nie sú uvedené všetky verzie produktov.

Dosah

Medium

Podrobnosti

Proprietary Code CVEs Description CVSS Base Score CVSS Vector String
CVE-2025-36582 Dell NetWorker, versions prior to 19.13.0.0, contains a Selection of Less-Secure Algorithm During Negotiation ('Algorithm Downgrade') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure. 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:NThis hyperlink is taking you to a website outside of Dell Technologies.

 

Proprietary Code CVEs Description CVSS Base Score CVSS Vector String
CVE-2025-36582 Dell NetWorker, versions prior to 19.13.0.0, contains a Selection of Less-Secure Algorithm During Negotiation ('Algorithm Downgrade') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure. 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:NThis hyperlink is taking you to a website outside of Dell Technologies.

 

Dell Technologies odporúča všetkým svojim zákazníkom, aby sa riadili nielen základným skóre CVSS, ale aj prechodným skóre a skóre závažnosti v konkrétnych prostrediach, na základe ktorého môžu vyhodnotiť celkové riziko vo vlastnom prostredí.

Dotknuté produkty a riešenie problému

Product Software/Firmware Affected Versions Remediated Versions Link
NetWorker NetWorker Management Console, NetWorker Web UI, NetWorker Authentication Service Versions prior to 19.13.0.0 Version 19.13.0.0 or later NetWorker Downloads Area

 

Product Software/Firmware Affected Versions Remediated Versions Link
NetWorker NetWorker Management Console, NetWorker Web UI, NetWorker Authentication Service Versions prior to 19.13.0.0 Version 19.13.0.0 or later NetWorker Downloads Area

 

Notes:

  1. The Affected Products and Remediation table above may not be a comprehensive list of all affected supported versions and may be updated as more information becomes available.
  2. Versions prior to 19.13.0.0 means 19.12.x, 19.11.x, 19.10.x, 19.9.x, and 19.8.x family of releases that are still under standard support. For more information refer to Dell End-of-Life Product List for Converged Infrastructure and Storage
  3. Unless specified as impacted, the term “later releases” encompasses all NetWorker releases, under standard support, that are of a higher minor or major version than the specified release. Dell recommends that you always upgrade to the latest release/version for your product.
  4. Platforms: Windows & Linux (All variants and flavors are impacted).

Alternatívne riešenia a zmiernenia

None

História revízií

RevisionDateDescription
1.02025-07-01Initial Release
2.02025-08-19Updated the 'Affected and Remediated Versions' and 'Additional Information' sections
3.02025-12-31
Updated the CVE description to clarify the impact

 

Súvisiace informácie

Dotknuté produkty

NetWorker Family
Vlastnosti článku
Číslo článku: 000338757
Typ článku: Dell Security Advisory
Dátum poslednej úpravy: 31 dec 2025
Nájdite odpovede na svoje otázky od ostatných používateľov spoločnosti Dell
Služby podpory
Skontrolujte, či sa na vaše zariadenie vzťahujú služby podpory.