7.8
CVE-2025-38747
- EPSS 0.02%
- Veröffentlicht 06.08.2025 19:48:46
- Zuletzt bearbeitet 18.08.2025 15:36:36
- Quelle security_alert@emc.com
- CVE-Watchlists
- Unerledigt
Dell SupportAssist OS Recovery, versions prior to 5.5.14.0, contain a Creation of Temporary File With Insecure Permissions vulnerability. A local authenticated attacker could potentially exploit this vulnerability, leading to Elevation of Privileges.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Dell ≫ Supportassist Os Recovery Version < 5.5.14.0
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.02% | 0.066 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security_alert@emc.com | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-378 Creation of Temporary File With Insecure Permissions
Opening temporary files without appropriate measures or controls can leave the file, its contents and any function that it impacts vulnerable to attack.