Dell SupportAssist Multiple Vulnerabilities (DSA-2022-139)

critical Nessus Plugin ID 180503

Synopsis

The remote Windows host contains a Dell SupportAssist that is affected by multiple vulnerabilities.

Description

According to its self-reported version number, the version of Dell SupportAssist Client is affected by multiple vulnerabilities.

- Dell SupportAssist Client Consumer versions (3.10.4 and versions prior) and Dell SupportAssist Client Commercial versions (3.1.1 and versions prior) contain an arbitrary file deletion vulnerability.
Authenticated non-admin user could exploit the issue and delete arbitrary files on the system.
(CVE-2022-29093)

- Dell SupportAssist Client Consumer versions (3.10.4 and versions prior) and Dell SupportAssist Client Commercial versions (3.1.1 and versions prior) contain an arbitrary file deletion/overwrite vulnerability.
Authenticated non-admin user could exploit the issue and delete or overwrite arbitrary files on the system. (CVE-2022-29094)

- Dell SupportAssist Client Consumer versions (3.10.4 and prior) and Dell SupportAssist Client Commercial versions (3.1.1 and prior) contain a cross-site scripting vulnerability. A remote unauthenticated malicious user could potentially exploit this vulnerability under specific conditions leading to execution of malicious code on a vulnerable system. (CVE-2022-29095)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update Dell SupportAssist Client Consumer to version 3.11.4, Dell Client Commercial 3.2.0 or later.

See Also

http://www.nessus.org/u?936a539e

Plugin Details

Severity: Critical

ID: 180503

File Name: dell_support_assist_DSA-2022-139.nasl

Version: 1.1

Type: local

Agent: windows

Family: Windows

Published: 9/5/2023

Updated: 9/6/2023

Supported Sensors: Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.5

CVSS v2

Risk Factor: High

Base Score: 7.6

Temporal Score: 5.6

Vector: CVSS2#AV:N/AC:H/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2022-29095

CVSS v3

Risk Factor: Critical

Base Score: 9.6

Temporal Score: 8.3

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:dell:supportassist

Required KB Items: installed_sw/Dell SupportAssist

Exploit Ease: No known exploits are available

Patch Publication Date: 6/9/2022

Vulnerability Publication Date: 6/9/2022

Reference Information

CVE: CVE-2022-29093, CVE-2022-29094, CVE-2022-29095