CVE-2025-36582
Unknown
Unknown - Not Provided
BaseFortify
Publication date: 2025-07-01
Last updated on: 2025-08-14
Assigner: Dell
Description
Description
Dell NetWorker, versions 19.12.0.1 and prior, contains a Selection of Less-Secure Algorithm During Negotiation ('Algorithm Downgrade') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| dell | networker | to 19.13 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-757 | A protocol or its implementation supports interaction between multiple actors and allows those actors to negotiate which algorithm should be used as a protection mechanism such as encryption or authentication, but it does not select the strongest algorithm that is available to both parties. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability in Dell NetWorker (versions 19.12.0.1 and prior) is an 'Algorithm Downgrade' issue where the software selects less-secure algorithms during negotiation. An unauthenticated attacker with remote access could exploit this to cause information disclosure.
How can this vulnerability impact me? :
The vulnerability could allow an unauthenticated remote attacker to gain access to sensitive information by exploiting the use of less-secure algorithms, potentially leading to information disclosure.
Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70