Dell SupportAssist OS Recovery Insertion of Sensitive Information Vulnerability

Vulnerability

A vulnerability exists in Dell SupportAssist OS Recovery versions prior to 5.5.15.0, allowing for the insertion of sensitive information into files or directories that are externally accessible. This issue could be exploited by a low-privileged attacker with local access, potentially leading to unauthorized information exposure.

Impact

Exploitation of this vulnerability could result in unauthorized access to sensitive information.

Remediation

Users can update to Dell SupportAssist OS Recovery version 5.5.15.0 or later. Instructions for verifying the current version and updating the application are available in the Dell Security Advisory DSA-2025-403.

Added: Oct 27, 2025, 7:21 PM
Updated: Oct 27, 2025, 7:21 PM

Vulnerability Rating

Custom Algorithm
spread
7.8
impact
2.5
exploitability
3.3
remediation
7.7
relevance
0.8
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.