Lucene search

K
cvelistDellCVELIST:CVE-2019-3718
HistoryApr 18, 2019 - 7:58 p.m.

CVE-2019-3718

2019-04-1819:58:22
dell
www.cve.org
9

CVSS3

7.6

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H

AI Score

8.8

Confidence

High

EPSS

0.001

Percentile

35.1%

Dell SupportAssist Client versions prior to 3.2.0.90 contain an improper origin validation vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability to attempt CSRF attacks on users of the impacted systems.

CNA Affected

[
  {
    "product": "SupportAssist Client",
    "vendor": "Dell",
    "versions": [
      {
        "lessThan": "3.2.0.90",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

7.6

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H

AI Score

8.8

Confidence

High

EPSS

0.001

Percentile

35.1%

Related for CVELIST:CVE-2019-3718