CVE Vulnerabilities

CVE-2025-46684

Creation of Temporary File With Insecure Permissions

Published: Jan 13, 2026 | Modified: Feb 13, 2026
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Dell SupportAssist OS Recovery, versions prior to 5.5.15.1, contain a Creation of Temporary File With Insecure Permissions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information Tampering.

Weakness

Opening temporary files without appropriate measures or controls can leave the file, its contents and any function that it impacts vulnerable to attack.

Affected Software

NameVendorStart VersionEnd Version
Supportassist_os_recoveryDell*5.5.15.1 (excluding)

Potential Mitigations

References