CVE-2023-25544
Description
Dell NetWorker versions 19.5 and earlier contain 'Apache Tomcat' version disclosure vulnerability. A NetWorker server user with remote access to NetWorker clients may potentially exploit this vulnerability and may launch target-specific attacks.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Dell NetWorker versions 19.5 and earlier expose Apache Tomcat version information, allowing remote attackers to launch target-specific attacks.
Vulnerability
Dell NetWorker versions 19.5 and earlier expose the Apache Tomcat version via an unspecified disclosure vector [1]. This is a version disclosure vulnerability that does not require authentication or user interaction [1]. The affected component is the Apache Tomcat server bundled with NetWorker [1].
Exploitation
An attacker with remote network access to NetWorker clients can exploit this vulnerability by probing the Apache Tomcat service to identify its version [1]. No authentication or special privileges are needed, as the version is disclosed without any access control [1]. The exact sequence of steps is not detailed in the available references, but the attack vector is network-based with low complexity [1].
Impact
Successful exploitation allows the attacker to obtain the Apache Tomcat version [1]. While this is primarily a confidentiality impact (information disclosure), the knowledge can be used to launch further target-specific attacks [1]. The CVSS v3.1 base score is 7.5 (High), with a vector of AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N [1].
Mitigation
Dell has released a security update to address this vulnerability [1]. Affected users should apply the latest patches for Dell NetWorker as recommended in DSA-2023-058 [1]. There is no publicly documented workaround beyond applying the fix [1].
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Dell/Dell NetWorker, NVEv5Range: 19.5 and earlier versions
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.