CVE-2022-34389: Medium severity dell supportassist vulnerability
Dell SupportAssist contains a rate limit bypass issues in screenmeet API third party component. An unauthenticated attacker could potentially exploit this vulnerability and impersonate a legitimate dell customer to a dell support technician.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-34389?
CVE-2022-34389 refers to a vulnerability in Dell SupportAssist that allows a rate limit bypass in the screenmeet API third-party component.
How can an attacker exploit CVE-2022-34389?
An unauthenticated attacker could exploit CVE-2022-34389 to impersonate a legitimate Dell customer to a Dell support technician.
What is the severity of CVE-2022-34389?
CVE-2022-34389 has a severity rating of medium, with a severity value of 5.3.
Which software versions are affected by CVE-2022-34389?
Dell SupportAssist for Business PCs up to version 3.3.0 and Dell SupportAssist for Home PCs up to version 3.12.3 are affected by CVE-2022-34389.
How can I fix CVE-2022-34389?
To fix CVE-2022-34389, Dell recommends updating to the latest version of Dell SupportAssist for Business PCs or Dell SupportAssist for Home PCs.