First published: Fri Feb 10 2023(Updated: )
SupportAssist for Home PCs (versions 3.11.4 and prior) contain an insufficient session expiration Vulnerability. An authenticated non-admin user can be able to obtain the refresh token and that leads to reuse the access token and fetch sensitive information.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dell SupportAssist for Home PCs | <=3.11.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-34392 is a vulnerability found in SupportAssist for Home PCs (versions 3.11.4 and prior) which allows an authenticated non-admin user to obtain a refresh token and reuse the access token to fetch sensitive information.
CVE-2022-34392 has a medium severity rating with a CVSS score of 5.5.
SupportAssist for Home PCs versions 3.11.4 and prior are affected by CVE-2022-34392.
An attacker needs to be an authenticated non-admin user to exploit CVE-2022-34392 by obtaining and reusing tokens to fetch sensitive information.
Yes, Dell has released a fix for CVE-2022-34392. It is recommended to update to the latest version of SupportAssist for Home PCs.