7.1
CVE-2022-34388
- EPSS 0.04%
- Published 11.02.2023 01:23:24
- Last modified 21.11.2024 07:09:24
- Source security_alert@emc.com
- Teams watchlist Login
- Open Login
Dell SupportAssist for Home PCs (version 3.11.4 and prior) and SupportAssist for Business PCs (version 3.2.0 and prior) contain information disclosure vulnerability. A local malicious user with low privileges could exploit this vulnerability to view and modify sensitive information in the database of the affected application.
Data is provided by the National Vulnerability Database (NVD)
Dell ≫ Supportassist For Business Pcs Version <= 3.2.0
Dell ≫ Supportassist For Home Pcs Version <= 3.11.4
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.04% | 0.115 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 7.1 | 1.8 | 5.2 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
|
security_alert@emc.com | 7.1 | 1.8 | 5.2 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
|
CWE-312 Cleartext Storage of Sensitive Information
The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.
CWE-318 Cleartext Storage of Sensitive Information in Executable
The product stores sensitive information in cleartext in an executable.