CVE-2022-34392: Medium severity dell supportassist vulnerability
SupportAssist for Home PCs (versions 3.11.4 and prior) contain an insufficient session expiration Vulnerability. An authenticated non-admin user can be able to obtain the refresh token and that leads to reuse the access token and fetch sensitive information.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-34392?
CVE-2022-34392 is a vulnerability found in SupportAssist for Home PCs (versions 3.11.4 and prior) which allows an authenticated non-admin user to obtain a refresh token and reuse the access token to fetch sensitive information.
How severe is CVE-2022-34392?
CVE-2022-34392 has a medium severity rating with a CVSS score of 5.5.
What software versions are affected by CVE-2022-34392?
SupportAssist for Home PCs versions 3.11.4 and prior are affected by CVE-2022-34392.
How can an attacker exploit CVE-2022-34392?
An attacker needs to be an authenticated non-admin user to exploit CVE-2022-34392 by obtaining and reusing tokens to fetch sensitive information.
Is there a fix available for CVE-2022-34392?
Yes, Dell has released a fix for CVE-2022-34392. It is recommended to update to the latest version of SupportAssist for Home PCs.