← Vulnerability feed

Vulnerability record · CVE-2025-38746 · published 6 August 2025

CVE-2025-38746: Dell supportassist os recovery information exposure vulnerability

Dell · Supportassist Os Recovery

Dell SupportAssist OS Recovery, versions prior to 5.5.14.0, contains an Exposure of Sensitive Information to an Unauthorized Actor vulnerability. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Information Disclosure.

2.4 CVSS 3.1 Low EPSS 0.18% · top 93.3% CWE-200 · Information exposure
2.4CVSS 3.1 base score
0.18%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

Dell SupportAssist OS Recovery, versions prior to 5.5.14.0, contains an Exposure of Sensitive Information to an Unauthorized Actor vulnerability. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Information Disclosure.

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-38746 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2025-46685Dell supportassist os recovery vulnerabilityDell SupportAssist OS Recovery, versions prior to 5.5.15.1, contain a Creation of Temporary File With Insecure Permissions vulnerability. A low privi…EPSS 0.10%7.8CVE-2025-38747Dell supportassist os recovery vulnerabilityDell SupportAssist OS Recovery, versions prior to 5.5.14.0, contain a Creation of Temporary File With Insecure Permissions vulnerability. A local aut…EPSS 0.15%7.8CVE-2025-22480Dell supportassist os recovery link following vulnerabilityDell SupportAssist OS Recovery versions prior to 5.5.13.1 contain a symbolic link attack vulnerability. A low-privileged attacker with local access c…EPSS 0.18%6.8CVE-2022-26865Dell supportassist os recovery authentication bypass via alternate path vulnerabilityDell Support Assist OS Recovery versions before 5.5.2 contain an Authentication Bypass vulnerability. An unauthenticated attacker with physical acces…EPSS 0.30%5.5CVE-2025-46684Dell supportassist os recovery vulnerabilityDell SupportAssist OS Recovery, versions prior to 5.5.15.1, contain a Creation of Temporary File With Insecure Permissions vulnerability. A low privi…EPSS 0.11%5.5CVE-2025-46602Dell supportassist os recovery vulnerabilityDell SupportAssist OS Recovery, versions prior to 5.5.15.0, contain an Insertion of Sensitive Information into Externally-Accessible File or Director…EPSS 0.11%5.9CVE-2025-68686FortiOS symbolic link patch bypass exposes sensitive informationFortiOS contains an information exposure flaw (CWE-200) that lets a remote unauthenticated attacker bypass the patch for the symbolic link persistenc…KEVEPSS 30%analysed7.5CVE-2026-20133Cisco Catalyst SD-WAN Manager insufficient file system restrictions expose dataCisco Catalyst SD-WAN Software has insufficient file system restrictions that let an attacker read sensitive files on the underlying operating system…KEVEPSS 32%analysed

Source: NIST National Vulnerability Database (record CVE-2025-38746), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.