7.1
CVE-2022-34388
- EPSS 0.04%
- Veröffentlicht 11.02.2023 01:23:24
- Zuletzt bearbeitet 21.11.2024 07:09:24
- Quelle security_alert@emc.com
- Teams Watchlist Login
- Unerledigt Login
Dell SupportAssist for Home PCs (version 3.11.4 and prior) and SupportAssist for Business PCs (version 3.2.0 and prior) contain information disclosure vulnerability. A local malicious user with low privileges could exploit this vulnerability to view and modify sensitive information in the database of the affected application.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Dell ≫ Supportassist For Business Pcs Version <= 3.2.0
Dell ≫ Supportassist For Home Pcs Version <= 3.11.4
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.04% | 0.115 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 7.1 | 1.8 | 5.2 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
|
security_alert@emc.com | 7.1 | 1.8 | 5.2 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
|
CWE-312 Cleartext Storage of Sensitive Information
The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.
CWE-318 Cleartext Storage of Sensitive Information in Executable
The product stores sensitive information in cleartext in an executable.