Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-22480

Опубликовано: 13 фев. 2025
Источник: nvd
CVSS3: 7
CVSS3: 7.8
EPSS Низкий

Описание

Dell SupportAssist OS Recovery versions prior to 5.5.13.1 contain a symbolic link attack vulnerability. A low-privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary file deletion and Elevation of Privileges.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:dell:supportassist_os_recovery:*:*:*:*:*:*:*:*
Версия до 5.5.13.1 (исключая)

EPSS

Процентиль: 3%
0.00017
Низкий

7 High

CVSS3

7.8 High

CVSS3

Дефекты

CWE-61
CWE-59

Связанные уязвимости

CVSS3: 7
github
12 месяцев назад

Dell SupportAssist OS Recovery versions prior to 5.5.13.1 contain a symbolic link attack vulnerability. A low-privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary file deletion and Elevation of Privileges.

EPSS

Процентиль: 3%
0.00017
Низкий

7 High

CVSS3

7.8 High

CVSS3

Дефекты

CWE-61
CWE-59