Home
LOW: 3.5 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:NDefault status
unaffected
Any version before 5.5.14.0
affected
Description
Dell SupportAssist OS Recovery, versions prior to 5.5.14.0, contains an Exposure of Sensitive Information to an Unauthorized Actor vulnerability. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Information Disclosure.
Problem types
CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
Product status
Any version before 5.5.14.0
Credits
Dell Technologies would like to thank bugzzzhunter for reporting this issue.
References
www.dell.com/support/kbdoc/en-us/000353093/dsa-2025-315