CVE-2025-36582

MEDIUM

Dell NetWorker < 19.13 - Unauthenticated Algorithm Downgrade

Title source: llm
STIX 2.1

Description

Dell NetWorker, versions 19.12.0.1 and prior, contains a Selection of Less-Secure Algorithm During Negotiation ('Algorithm Downgrade') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.

Scores

CVSS v3 4.8
EPSS 0.0030
EPSS Percentile 53.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-757
Status published
Products (1)
dell/networker < 19.13
Published Jul 01, 2025
Tracked Since Feb 18, 2026