Sensitive Information Exposure in Dell SupportAssist OS Recovery
CVE-2025-46602

4.4MEDIUM

Key Information:

Vendor

Dell

Vendor
CVE Published:
27 October 2025

What is CVE-2025-46602?

Dell SupportAssist OS Recovery versions prior to 5.5.15.0 possess a vulnerability that allows local, low-privileged attackers to exploit sensitive information. This flaw could lead to unauthorized access to confidential data stored in files or directories accessible externally, posing significant risks to user privacy and data security.

Affected Version(s)

SupportAssist OS Recovery < 5.5.15.0

References

CVSS V3.1

Score:
4.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dell Technologies would like to thank Marius Gabriel Mihai for reporting this issue.
.
CVE-2025-46602 : Sensitive Information Exposure in Dell SupportAssist OS Recovery