Sensitive Information Exposure in Dell SupportAssist OS Recovery
CVE-2025-46602
4.4MEDIUM
What is CVE-2025-46602?
Dell SupportAssist OS Recovery versions prior to 5.5.15.0 possess a vulnerability that allows local, low-privileged attackers to exploit sensitive information. This flaw could lead to unauthorized access to confidential data stored in files or directories accessible externally, posing significant risks to user privacy and data security.
Affected Version(s)
SupportAssist OS Recovery < 5.5.15.0
References
CVSS V3.1
Score:
4.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Dell Technologies would like to thank Marius Gabriel Mihai for reporting this issue.