High
Proprietary Code CVEs | Description | CVSS Base Score | CVSS Vector String |
CVE-2022-29092 | Dell SupportAssist Client Consumer versions (3.11.0 and versions prior) and Dell SupportAssist Client Commercial versions (3.2.0 and versions prior) contain a privilege escalation vulnerability. A non-admin user can exploit the vulnerability and gain admin access to the system. | 7.8 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
CVE-2022-29093 | Dell SupportAssist Client Consumer versions (3.10.4 and versions prior) and Dell SupportAssist Client Commercial versions (3.1.1 and versions prior) contain an arbitrary file deletion vulnerability. Authenticated non-admin user could exploit the issue and delete arbitrary files on the system. | 7.1 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H |
CVE-2022-29094 | Dell SupportAssist Client Consumer versions (3.10.4 and versions prior) and Dell SupportAssist Client Commercial versions (3.1.1 and versions prior) contain an arbitrary file deletion/overwrite vulnerability. Authenticated non-admin user could exploit the issue and delete or overwrite arbitrary files on the system. | 7.1 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H |
CVE-2022-29095 | Dell SupportAssist Client Consumer versions (3.10.4 and prior) and Dell SupportAssist Client Commercial versions (3.1.1 and prior) contain a cross-site scripting vulnerability. A remote unauthenticated malicious user could potentially exploit this vulnerability under specific conditions leading to execution of malicious code on a vulnerable system. | 8.3 | CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H |
Proprietary Code CVEs | Description | CVSS Base Score | CVSS Vector String |
CVE-2022-29092 | Dell SupportAssist Client Consumer versions (3.11.0 and versions prior) and Dell SupportAssist Client Commercial versions (3.2.0 and versions prior) contain a privilege escalation vulnerability. A non-admin user can exploit the vulnerability and gain admin access to the system. | 7.8 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
CVE-2022-29093 | Dell SupportAssist Client Consumer versions (3.10.4 and versions prior) and Dell SupportAssist Client Commercial versions (3.1.1 and versions prior) contain an arbitrary file deletion vulnerability. Authenticated non-admin user could exploit the issue and delete arbitrary files on the system. | 7.1 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H |
CVE-2022-29094 | Dell SupportAssist Client Consumer versions (3.10.4 and versions prior) and Dell SupportAssist Client Commercial versions (3.1.1 and versions prior) contain an arbitrary file deletion/overwrite vulnerability. Authenticated non-admin user could exploit the issue and delete or overwrite arbitrary files on the system. | 7.1 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H |
CVE-2022-29095 | Dell SupportAssist Client Consumer versions (3.10.4 and prior) and Dell SupportAssist Client Commercial versions (3.1.1 and prior) contain a cross-site scripting vulnerability. A remote unauthenticated malicious user could potentially exploit this vulnerability under specific conditions leading to execution of malicious code on a vulnerable system. | 8.3 | CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H |
CVEs Addressed | Product | Affected Versions | Updated Versions | Link to Update |
CVE-2022-29092 | Dell SupportAssist for Home PCs | Version 3.11.0 and earlier | N/A | There are two ways in which the customer can get the latest component which has the fix:
|
Dell SupportAssist for Business PCs | Version 3.2.0 and earlier | N/A | There are two ways in which the customer can get the latest component which has the fix:
|
|
CVE-2022-29093, CVE-2022-29094, and CVE-2022-29095 | Dell SupportAssist for Home PCs | 3.10.4 and earlier | 3.11.4 | SupportAssist for Home PCs Release Notes and User Guide |
Dell SupportAssist for Business PCs | 3.1.1 and earlier | 3.2.0 |
TechDirect Link for Admins Release Notes and User Guide |
CVEs Addressed | Product | Affected Versions | Updated Versions | Link to Update |
CVE-2022-29092 | Dell SupportAssist for Home PCs | Version 3.11.0 and earlier | N/A | There are two ways in which the customer can get the latest component which has the fix:
|
Dell SupportAssist for Business PCs | Version 3.2.0 and earlier | N/A | There are two ways in which the customer can get the latest component which has the fix:
|
|
CVE-2022-29093, CVE-2022-29094, and CVE-2022-29095 | Dell SupportAssist for Home PCs | 3.10.4 and earlier | 3.11.4 | SupportAssist for Home PCs Release Notes and User Guide |
Dell SupportAssist for Business PCs | 3.1.1 and earlier | 3.2.0 |
TechDirect Link for Admins Release Notes and User Guide |
Revision | Date | Description |
1.0 | 2022-06-09 | Initial Draft |
1.1 | 2022-06-27 | Updated affected products and remediation section |
Dell would like to thank Molybdenum for reporting CVE-2022-29092 and Patrick Murphy for reporting CVE-2022-29093 and CVE-2022-29094.