SupportAssist for Home PCs (versions 3.11.4 and prior) contain an insufficient session expiration Vulnerability. An authenticated non-admin user can be able to obtain the refresh token and that leads to reuse the access token and fetch sensitive information.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-37347 | SupportAssist for Home PCs (versions 3.11.4 and prior) contain an insufficient session expiration Vulnerability. An authenticated non-admin user can be able to obtain the refresh token and that leads to reuse the access token and fetch sensitive information. |
| Link | Providers |
|---|---|
| https://www.dell.com/support/kbdoc/000204114 |
|
Wed, 26 Mar 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: dell
Published:
Updated: 2025-03-26T15:19:54.301Z
Reserved: 2022-06-23T18:55:17.093Z
Link: CVE-2022-34392
Updated: 2024-08-03T09:07:16.133Z
Status : Modified
Published: 2023-02-11T01:23:24.353
Modified: 2024-11-21T07:09:25.447
Link: CVE-2022-34392
No data.
OpenCVE Enrichment
No data.
EUVD