Notification

Icon
Error

Dell SupportAssist CVE-2019-12280

Posted: Monday, June 24, 2019 9:15:20 AM(UTC)
Esben.D

Esben.D

Member Administration Original PosterPosts: 2,186
0
Like
Just shortly after the previous vulnerability in SupportAssist, another one has been discovered. You can find the details in our blog post.

The report below will provide an overview of all Dell SupportAssist for Home PCs versions and checks whether the version is on the recommended 3.2.2 or higher.

Code:
Select Distinct Top 1000000 tblAssets.AssetID,
  tblAssets.AssetName,
  tblAssets.Domain,
  tsysAssetTypes.AssetTypename As AssetType,
  tblAssets.Username,
  tblAssets.Userdomain,
  tsysAssetTypes.AssetTypeIcon10 As icon,
  tblAssets.IPAddress,
  tblSoftwareUni.softwareName As Software,
  tblSoftware.softwareVersion As Version,
  tblSoftwareUni.SoftwarePublisher As Publisher,
  Case
    When tblSoftwareUni.softwareName Like '%SupportAssist' And
      tblSoftware.softwareVersion < '3.2.2' Then 'Vulnerable'
    Else 'Safe'
  End As Vulnerable,
  tsysIPLocations.IPLocation,
  tblAssetCustom.Manufacturer,
  tblAssetCustom.Model,
  tsysOS.OSname As OS,
  tblAssets.SP,
  tblAssets.Lastseen,
  tblAssets.Lasttried,
  tblSoftware.Lastchanged As SoftwareLastChanged,
  Case
    When tblSoftwareUni.softwareName Like '%SupportAssist' And
      tblSoftware.softwareVersion < '3.2.2' Then '#ffadad'
    Else '#d4f4be'
  End As backgroundcolor
From tblAssets
  Inner Join tblAssetCustom On tblAssets.AssetID = tblAssetCustom.AssetID
  Inner Join tsysAssetTypes On tsysAssetTypes.AssetType = tblAssets.Assettype
  Inner Join tsysIPLocations On tsysIPLocations.LocationID =
    tblAssets.LocationID
  Inner Join tblState On tblState.State = tblAssetCustom.State
  Inner Join tblSoftware On tblAssets.AssetID = tblSoftware.AssetID
  Inner Join tblSoftwareUni On tblSoftwareUni.SoftID = tblSoftware.softID
  Left Join tsysOS On tsysOS.OScode = tblAssets.OScode
Where tblSoftwareUni.softwareName Like '%SupportAssist' And tblState.Statename =
  'Active'
Order By tblAssets.IPAddress Desc

Active Discussions

Lansweeper Lansweeper Dark Theme
by  mrobbins   Go to last post Go to first unread
Last post: Yesterday at 5:38:01 PM(UTC)
Lansweeper Detect Docking Stations
by  GlenH  
Go to last post Go to first unread
Last post: Yesterday at 3:52:13 PM(UTC)
Lansweeper Exclude non-windows assets from scanning by assetname
by  rapheren   Go to last post Go to first unread
Last post: Yesterday at 1:18:12 PM(UTC)
Lansweeper HTTPS Certifikate untrusted
by  pskup  
Go to last post Go to first unread
Last post: Yesterday at 9:20:07 AM(UTC)
Lansweeper Migrate to new host but without SQL
by  pskup   Go to last post Go to first unread
Last post: Yesterday at 9:03:14 AM(UTC)
Lansweeper Object reference error after updating to 10.2.0.0
by  Erik.T  
Go to last post Go to first unread
Last post: Yesterday at 8:10:25 AM(UTC)
Lansweeper Custom reporting - Asset Groups and AD Description
by  rbshawn   Go to last post Go to first unread
Last post: 6/29/2022 10:54:10 PM(UTC)
Lansweeper A FIX for an odd Scan Error WMI/DCOM from scanning server
by  danielm  
Go to last post Go to first unread
Last post: 6/29/2022 10:14:44 PM(UTC)