CVE-2022-29094

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
10/06/2022
Last modified:
17/06/2022

Description

Dell SupportAssist Client Consumer versions (3.10.4 and versions prior) and Dell SupportAssist Client Commercial versions (3.1.1 and versions prior) contain an arbitrary file deletion/overwrite vulnerability. Authenticated non-admin user could exploit the issue and delete or overwrite arbitrary files on the system.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:dell:supportassist_for_business_pcs:*:*:*:*:*:*:*:* 3.1.1 (including)
cpe:2.3:a:dell:supportassist_for_home_pcs:*:*:*:*:*:*:*:* 3.10.4 (including)