← Vulnerability feed

Vulnerability record · CVE-2022-34458 · published 1 February 2023

CVE-2022-34458: Dell alienware update vulnerability

Dell · Alienware Update

Dell Command | Update, Dell Update, and Alienware Update versions prior to 4.7 contain a Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in download operation component. A local malicious user could potentially exploit this vulnerability leading to the disclosure of confidential data.

5.5 CVSS 3.1 Medium EPSS 0.18% · top 93.2% CWE-497 · CWE-497
5.5CVSS 3.1 base score
0.18%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Dell Command | Update, Dell Update, and Alienware Update versions prior to 4.7 contain a Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in download operation component. A local malicious user could potentially exploit this vulnerability leading to the disclosure of confidential data.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-34458 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2026-58565Dell command update missing authorization vulnerabilityDell Command Update (DCU), versions prior to 5.7.1, contain a Missing Authorization vulnerability. A low privileged attacker with local access could …EPSS 0.14%7.8CVE-2026-58564Dell command update incorrect default permissions vulnerabilityDell Command Update (DCU), versions prior to 5.7.1, contain an Incorrect Default Permissions vulnerability. A low privileged attacker with local acce…EPSS 0.14%7.8CVE-2026-53477Dell command update toctou race condition vulnerabilityDell Command Update (DCU), versions prior to 5.7.1, contain a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability. A low privileged attac…EPSS 0.12%7.8CVE-2026-49816Dell command update deserialization of untrusted data vulnerabilityDell Command Update (DCU), versions prior to 5.7.1, contain a Deserialization of Untrusted Data vulnerability. A low privileged attacker with local a…EPSS 0.31%7.8CVE-2026-49817Dell command update deserialization of untrusted data vulnerabilityDell Command Update (DCU), versions prior to 5.7.1, contain a Deserialization of Untrusted Data vulnerability. A low privileged attacker with local a…EPSS 0.31%7.8CVE-2022-34384Dell alienware update execution with unnecessary privileges vulnerabilityDell SupportAssist Client Consumer (version 3.11.1 and prior), SupportAssist Client Commercial (version 3.2 and prior), Dell Command | Update, Dell U…EPSS 0.23%7.8CVE-2022-34459Dell alienware update improper verification of cryptographic signature vulnerabilityDell Command | Update, Dell Update, and Alienware Update versions prior to 4.7 contain a improper verification of cryptographic signature in get appl…EPSS 0.15%7.8CVE-2022-34382Dell alienware update vulnerabilityDell Command Update, Dell Update and Alienware Update versions prior to 4.6.0 contains a Local Privilege Escalation Vulnerability in the custom catal…EPSS 0.19%

Source: NIST National Vulnerability Database (record CVE-2022-34458), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.