CVE-2022-34392
11.02.2023, 01:23
SupportAssist for Home PCs (versions 3.11.4 and prior) contain an insufficient session expiration Vulnerability. An authenticated non-admin user can be able to obtain the refresh token and that leads to reuse the access token and fetch sensitive information.Enginsight
Vendor | Product | Version |
---|---|---|
dell | supportassist_for_home_pcs | 𝑥 ≤ 3.11.4 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration