First published: Fri Feb 10 2023(Updated: )
Dell SupportAssist contains a rate limit bypass issues in screenmeet API third party component. An unauthenticated attacker could potentially exploit this vulnerability and impersonate a legitimate dell customer to a dell support technician.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dell SupportAssist for Business PCs | <3.3.0 | |
Dell SupportAssist for Home PCs | <3.12.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-34389 refers to a vulnerability in Dell SupportAssist that allows a rate limit bypass in the screenmeet API third-party component.
An unauthenticated attacker could exploit CVE-2022-34389 to impersonate a legitimate Dell customer to a Dell support technician.
CVE-2022-34389 has a severity rating of medium, with a severity value of 5.3.
Dell SupportAssist for Business PCs up to version 3.3.0 and Dell SupportAssist for Home PCs up to version 3.12.3 are affected by CVE-2022-34389.
To fix CVE-2022-34389, Dell recommends updating to the latest version of Dell SupportAssist for Business PCs or Dell SupportAssist for Home PCs.