VulnerabilityModified
CVE-2019-3718
Dell SupportAssist Client versions prior to 3.2.0.90 contain an improper origin validation vulnerability.
HIGH 8.8EPSS 0.67%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.67%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Dell SupportAssist Client versions prior to 3.2.0.90 contain an improper origin validation vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability to attempt CSRF attacks on users of the impacted systems.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 0.67% probability · 50th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-352
- Affected
- dell/supportassist
- Source
- security_alert@emc.com
References
- http://www.securityfocus.com/bid/108020Broken Link, Third Party Advisory, VDB Entry
- https://www.dell.com/support/article/us/en/19/sln316857/dsa-2019-051-dell-supportassist-client-multiple-vulnerabilities?lang=enVendor Advisory
- http://www.securityfocus.com/bid/108020Broken Link, Third Party Advisory, VDB Entry
- https://www.dell.com/support/article/us/en/19/sln316857/dsa-2019-051-dell-supportassist-client-multiple-vulnerabilities?lang=enVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.