DSA-2025-403: Security Update for Dell SupportAssist OS Recovery for an Insertion of Sensitive Information into Externally Accessible File or Directory Vulnerability

Summary: Dell SupportAssist OS Recovery remediation is available for an Insertion of Sensitive Information into Externally Accessible File or Directory vulnerability that could be exploited by malicious users to compromise the affected system. ...

This article applies to This article does not apply to This article is not tied to any specific product. Not all product versions are identified in this article.

Impact

Medium

Details

Proprietary Code CVE

Description

CVSS Base Score

CVSS Vector String

CVE-2025- 46602

Dell SupportAssist OS Recovery, versions prior to 5.5.15.0, contain an Insertion of Sensitive Information into Externally-Accessible File or Directory vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information exposure.

4.4

CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:NThis hyperlink is taking you to a website outside of Dell Technologies.

 

Proprietary Code CVE

Description

CVSS Base Score

CVSS Vector String

CVE-2025- 46602

Dell SupportAssist OS Recovery, versions prior to 5.5.15.0, contain an Insertion of Sensitive Information into Externally-Accessible File or Directory vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information exposure.

4.4

CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:NThis hyperlink is taking you to a website outside of Dell Technologies.

 

Dell Technologies recommends all customers consider both the CVSS base score and any relevant temporal and environmental scores that may impact the potential severity associated with a particular security vulnerability.

Affected Products & Remediation

Product

Affected Versions

Remediated Versions

Release date (MM/DD/YYYY)

Link

Dell SupportAssist OS Recovery

Versions prior to 5.5.15.0

Version 5.5.15.0 or later

10/24/2025

https://www.dell.com/support/kbdoc/en-us/000177401/restore-your-system-using-dell-supportassist-os-recovery

 

Product

Affected Versions

Remediated Versions

Release date (MM/DD/YYYY)

Link

Dell SupportAssist OS Recovery

Versions prior to 5.5.15.0

Version 5.5.15.0 or later

10/24/2025

https://www.dell.com/support/kbdoc/en-us/000177401/restore-your-system-using-dell-supportassist-os-recovery

 

Dell SupportAssist OS Recovery application assists in Disk Cloning, Reset, Repair functions.

To verify your device is running the remediated version of Dell SupportAssist OS Recovery, follow below steps:

  1. During boot, press F12 to enter boot settings.
  2. Select the SupportAssist OS Recovery option in boot menu.
  3. On load, in splash screen or from the About menu, verify the version information in the launched application.
  4. If version is 5.5.15.0 or later, then your device is running the remediated version.

OR

  1. Goto Control Panel -> Programs and Features.
  2. Check the version information for Dell SupportAssist Remediation.
  3. If version is 5.5.15.0 or later, then your device is running the remediated version.

 

If the version is lower than 5.5.15.0 version, please follow below steps to install the 5.5.15.0 version or later:

  1. Launch Dell SupportAssist OS Recovery application from Windows Start menu.
  2. Click on Update Software in Home page.
  3. Select the checkbox for “Check for Updates”.
  4. Click on Start button to install update.

Revision History

Revision

Date

Description

1.0

2025-10-27

Initial Release

 

Acknowledgements

CVE-2025-46602: Dell Technologies would like to thank Marius Gabriel Mihai for reporting this issue.

Related Information

Affected Products

SupportAssist OS Recovery
Article Properties
Article Number: 000382443
Article Type: Dell Security Advisory
Last Modified: 27 Oct 2025
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.