First published: Thu Jun 09 2022(Updated: )
Dell SupportAssist Client Consumer versions (3.10.4 and prior) and Dell SupportAssist Client Commercial versions (3.1.1 and prior) contain a cross-site scripting vulnerability. A remote unauthenticated malicious user could potentially exploit this vulnerability under specific conditions leading to execution of malicious code on a vulnerable system.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dell SupportAssist for Business PCs | <=3.1.1 | |
Dell SupportAssist for Home PCs | <=3.10.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-29095 is a cross-site scripting vulnerability in Dell SupportAssist Client Consumer versions (3.10.4 and prior) and Dell SupportAssist Client Commercial versions (3.1.1 and prior).
CVE-2022-29095 has a severity rating of 9.6, which is considered critical.
Dell SupportAssist for Home PCs versions up to 3.10.4 and Dell SupportAssist for Business PCs versions up to 3.1.1 are affected by CVE-2022-29095.
CVE-2022-29095 is associated with CWE-79 and CWE-16.
More information about CVE-2022-29095 can be found at the following reference: [Dell Security Advisory DSA-2022-139](https://www.dell.com/support/kbdoc/en-us/000200456/dsa-2022-139-dell-supportassist-for-home-pcs-and-business-pcs-security-update-for-multiple-security-vulnerabilities).