Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-34392

Опубликовано: 11 фев. 2023
Источник: nvd
CVSS3: 5.5
EPSS Низкий

Описание

SupportAssist for Home PCs (versions 3.11.4 and prior) contain an insufficient session expiration Vulnerability. An authenticated non-admin user can be able to obtain the refresh token and that leads to reuse the access token and fetch sensitive information.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:dell:supportassist_for_home_pcs:*:*:*:*:*:*:*:*
Версия до 3.11.4 (включая)

EPSS

Процентиль: 23%
0.00077
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-613
CWE-613

Связанные уязвимости

CVSS3: 5.5
github
почти 3 года назад

SupportAssist for Home PCs (versions 3.11.4 and prior) contain an insufficient session expiration Vulnerability. An authenticated non-admin user can be able to obtain the refresh token and that leads to reuse the access token and fetch sensitive information.

EPSS

Процентиль: 23%
0.00077
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-613
CWE-613