CVE-2025-38746

Dell SupportAssist OS Recovery, versions prior to 5.5.14.0, contains an Exposure of Sensitive Information to an Unauthorized Actor vulnerability. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Information Disclosure.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:dell:supportassist_os_recovery:*:*:*:*:*:*:*:*

History

18 Aug 2025, 15:38

Type Values Removed Values Added
References () https://www.dell.com/support/kbdoc/en-us/000353093/dsa-2025-315 - () https://www.dell.com/support/kbdoc/en-us/000353093/dsa-2025-315 - Vendor Advisory
First Time Dell
Dell supportassist Os Recovery
CPE cpe:2.3:a:dell:supportassist_os_recovery:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 2.4

06 Aug 2025, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-06 20:15

Updated : 2025-08-18 15:38


NVD link : CVE-2025-38746

Mitre link : CVE-2025-38746


JSON object : View

Products Affected

dell

  • supportassist_os_recovery
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor