Allele Security Alert
ASA-2019-00261
Identifier(s)
ASA-2019-00261, CVE-2019-3718, DSA-2019-051
Title
Improper Origin Validation
Vendor(s)
Dell
Product(s)
Dell SupportAssist Client
Affected version(s)
Dell SupportAssist Client versions prior to 3.2.0.90
Fixed version(s)
Dell SupportAssist Client version 3.2.0.90 and later
Proof of concept
Unknown
Description
Dell SupportAssist Client versions prior to 3.2.0.90 contain an improper origin validation vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability to attempt Cross-Site Request Forgery (CSRF) attacks on users of the impacted systems.
Technical details
Unknown
Credits
John C. Hennessy-ReCar
Reference(s)
DSA-2019-051: Dell SupportAssist Client Multiple Vulnerabilities
https://www.dell.com/support/article/us/en/04/sln316857/dsa-2019-051-dell-supportassist-client-multiple-vulnerabilities?lang=en
CVE-2019-3718
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-3718
CVE-2019-3718
https://nvd.nist.gov/vuln/detail/CVE-2019-3718
If there is any error in this alert or you wish a comprehensive analysis, let us know.
Last modified: May 11, 2019