VYPR
Unrated severityNVD Advisory· Published Feb 10, 2023· Updated Mar 26, 2025

CVE-2022-34392

CVE-2022-34392

Description

SupportAssist for Home PCs (versions 3.11.4 and prior) contain an insufficient session expiration Vulnerability. An authenticated non-admin user can be able to obtain the refresh token and that leads to reuse the access token and fetch sensitive information.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Dell SupportAssist for Home PCs 3.11.4 and prior fail to expire sessions, allowing a non-admin user to reuse a refresh token and access sensitive information.

Vulnerability

CVE-2022-34392 affects Dell SupportAssist for Home PCs versions 3.11.4 and prior [1]. The software implements insufficient session expiration, meaning that after a user authenticates, their refresh token does not become invalid on schedule [1]. This flaw exists in the token lifecycle management of the application, allowing a valid refresh token to be reused beyond its intended expiration window.

Exploitation

An attacker must already be an authenticated, non-admin user of SupportAssist on the same PC [1]. No special privileges are required beyond standard authentication. The attacker can obtain the refresh token from their own session and, because the token has not expired, reuse it to obtain new access tokens at will [1]. This can be done repeatedly without triggering any re-authentication or other controls.

Impact

A successful attack leads to unauthorized reuse of an access token, which the attacker can then use to fetch sensitive information that their account is otherwise permitted to view [1]. The impact is limited to information disclosure (confidentiality) but does not grant additional privileges beyond what the authenticated non-admin user already has [1].

Mitigation

Dell has released an update resolving this vulnerability; users should upgrade to a version later than 3.11.4 [1]. For current information, refer to Dell security advisory DSA-2022-190 [1]. No workaround has been published.

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.