ZeroHour

CVE-2022-34392

CVSS 3.1
5.5 medium
EPSS
<1%p6
Published
()
Modified
Description

SupportAssist for Home PCs (versions 3.11.4 and prior) contain an insufficient session expiration Vulnerability. An authenticated non-admin user can be able to obtain the refresh token and that leads to reuse the access token and fetch sensitive information.

Vendors
dell
Products
supportassist for home pcs
Weakness
CWE-613
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.