First published: Wed Feb 01 2023(Updated: )
Dell Command | Update, Dell Update, and Alienware Update versions prior to 4.7 contain a Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in download operation component. A local malicious user could potentially exploit this vulnerability leading to the disclosure of confidential data.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dell Alienware Update | <4.7.1 | |
Dell Command Update | <4.7.1 | |
Dell Update | <4.7.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-34458 is a vulnerability in Dell Command | Update, Dell Update, and Alienware Update versions prior to 4.7 that allows exposure of sensitive system information to an unauthorized control sphere during the download operation.
CVE-2022-34458 has a severity score of 5.5, which is considered medium.
Dell Alienware Update, Dell Command Update, and Dell Update versions up to but excluding 4.7.1 are affected by CVE-2022-34458.
A local malicious user could potentially exploit CVE-2022-34458 by taking advantage of the vulnerability in the download operation component, leading to the disclosure of sensitive system information.
To fix CVE-2022-34458, it is recommended to update Dell Alienware Update, Dell Command Update, and Dell Update to version 4.7.1 or later.