CVE Details
Basic Information
| Title | CVE-2025-38746 |
|---|---|
| Type | cve |
| Published | 2025-08-06T19:53:05.549Z |
| Modified | 2025-08-06T19:59:14.486Z |
Product Information
| Vendor | Dell |
|---|---|
| Product | SupportAssist OS Recovery |
| Version | N/A |
CVSS Information
| Base Score | 3.5 (LOW) |
|---|---|
| Attack Vector | CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
AI Analysis
| AI Description | Dell SupportAssist OS Recovery versions before 5.5.14.0 have a vulnerability that exposes sensitive information. An attacker with physical access could exploit this to disclose information. This is a moderate risk due to the need for physical access. |
|---|---|
| AI Severity | Medium |
| AI Vendor | Dell |
| AI Product | SupportAssist OS Recovery |
| AI Version | Versions prior to 5.5.14.0 |
Affected Products
- Dell SupportAssist OS Recovery N/A
Additional Information
| CWE List | CWE-200 |
|---|---|
| Source | dell |
Description
Dell SupportAssist OS Recovery, versions prior to 5.5.14.0, contains an Exposure of Sensitive Information to an Unauthorized Actor vulnerability. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Information Disclosure.