Dell Wyse Proprietary Os vulnerabilities
14 known vulnerabilities affecting dell/wyse_proprietary_os.
Total CVEs
14
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH7MEDIUM6
Vulnerabilities
Page 1 of 1
CVE-2025-27688HIGHCVSS 7.8≥ N/A, < ThinOS 25022025-03-18
CVE-2025-27688 [HIGH] CWE-732 CVE-2025-27688: Dell ThinOS 2408 and prior, contains an improper permissions vulnerability. A low privileged attacke
Dell ThinOS 2408 and prior, contains an improper permissions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.
nvd
CVE-2025-26331HIGHCVSS 7.8≥ N/A, < ThinOS 25022025-03-07
CVE-2025-26331 [HIGH] CWE-77 CVE-2025-26331: Dell ThinOS 2411 and prior, contains an Improper Neutralization of Special Elements used in a Comman
Dell ThinOS 2411 and prior, contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary code execution.
nvd
CVE-2024-53289HIGHCVSS 7.0vThinOS 24082024-12-11
CVE-2024-53289 [HIGH] CWE-367 CVE-2024-53289: Dell ThinOS version 2408 contains a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability.
Dell ThinOS version 2408 contains a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.
nvd
CVE-2024-53290HIGHCVSS 8.4vThinOS 24082024-12-11
CVE-2024-53290 [HIGH] CWE-77 CVE-2024-53290: Dell ThinOS version 2408 contains an Improper Neutralization of Special Elements used in a Command (
Dell ThinOS version 2408 contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Command execution
nvd
CVE-2024-42423HIGHCVSS 7.1vThinOS 2311vThinOS 24022024-09-10
CVE-2024-42423 [HIGH] CWE-863 CVE-2024-42423: Citrix Workspace App version 23.9.0.24.4 on Dell ThinOS 2311 contains an Incorrect Authorization vul
Citrix Workspace App version 23.9.0.24.4 on Dell ThinOS 2311 contains an Incorrect Authorization vulnerability when Citrix CEB is enabled for WebLogin. A local unauthenticated user with low privileges may potentially exploit this vulnerability to bypass existing controls and perform unauthorized actions leading to information disclosure and tampering.
nvd
CVE-2024-42427HIGHCVSS 7.6vDell ThinOS 2402vDell ThinOS 24052024-09-10
CVE-2024-42427 [HIGH] CWE-77 CVE-2024-42427: Dell ThinOS versions 2402 and 2405, contains an Improper Neutralization of Special Elements used in
Dell ThinOS versions 2402 and 2405, contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Elevation of privileges.
nvd
CVE-2024-28963MEDIUMCVSS 5.5≥ N/A, ≤ 1.0.0.72024-04-24
CVE-2024-28963 [MEDIUM] CWE-200 CVE-2024-28963: Telemetry Dashboard v1.0.0.7 for Dell ThinOS 2402 contains a sensitive information disclosure vulner
Telemetry Dashboard v1.0.0.7 for Dell ThinOS 2402 contains a sensitive information disclosure vulnerability. An unauthenticated user with local access to the device could exploit this vulnerability to read sensitive proxy settings information.
nvd
CVE-2023-32447MEDIUMCVSS 5.5v2303(9.4.1141) and below2023-07-20
CVE-2023-32447 [MEDIUM] CWE-312 CVE-2023-32447:
Dell Wyse ThinOS versions prior to 2306 (9.4.2103) contain a sensitive information disclosure vulne
Dell Wyse ThinOS versions prior to 2306 (9.4.2103) contain a sensitive information disclosure vulnerability. A malicious user with local access to the device could exploit this vulnerability to read sensitive information written to the log files.
nvd
CVE-2023-32455MEDIUMCVSS 5.5v2208 (9.3.2102) and below 2023-07-20
CVE-2023-32455 [MEDIUM] CWE-312 CVE-2023-32455:
Dell Wyse ThinOS versions prior to 2208 (9.3.2102) contain a sensitive information disclosure vulne
Dell Wyse ThinOS versions prior to 2208 (9.3.2102) contain a sensitive information disclosure vulnerability. An unauthenticated malicious user with local access to the device could exploit this vulnerability to read sensitive information written to the log files.
nvd
CVE-2023-32446MEDIUMCVSS 5.5v2303 (9.4.1141)2023-07-20
CVE-2023-32446 [MEDIUM] CWE-312 CVE-2023-32446:
Dell Wyse ThinOS versions prior to 2303 (9.4.1141) contain a sensitive information disclosure vulne
Dell Wyse ThinOS versions prior to 2303 (9.4.1141) contain a sensitive information disclosure vulnerability. An unauthenticated malicious user with local access to the device could exploit this vulnerability to read sensitive information written to the log files.
nvd
CVE-2022-34402MEDIUMCVSS 4.9≥ unspecified, < ThinOS 22082022-10-10
CVE-2022-34402 [MEDIUM] CWE-1333 CVE-2022-34402: Dell Wyse ThinOS 2205 contains a Regular Expression Denial of Service Vulnerability in UI. An admin
Dell Wyse ThinOS 2205 contains a Regular Expression Denial of Service Vulnerability in UI. An admin privilege attacker could potentially exploit this vulnerability, leading to denial-of-service.
nvd
CVE-2021-21532MEDIUMCVSS 6.3≥ unspecified, < ThinOS 8.6 MR92021-04-02
CVE-2021-21532 [MEDIUM] CWE-16 CVE-2021-21532: Dell Wyse ThinOS 8.6 MR9 contains remediation for an improper management server validation vulnerabi
Dell Wyse ThinOS 8.6 MR9 contains remediation for an improper management server validation vulnerability that could be potentially exploited to redirect a client to an attacker-controlled management server, thus allowing the attacker to change the device configuration or certificate file.
nvd
CVE-2020-29492CRITICALCVSS 10.0≥ unspecified, < 8.62021-01-04
CVE-2020-29492 [CRITICAL] CWE-276 CVE-2020-29492: Dell Wyse ThinOS 8.6 and prior versions contain an insecure default configuration vulnerability. A r
Dell Wyse ThinOS 8.6 and prior versions contain an insecure default configuration vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability to access the writable file and manipulate the configuration of any target specific station.
nvd
CVE-2020-29491HIGHCVSS 8.6≥ unspecified, < 8.62021-01-04
CVE-2020-29491 [HIGH] CWE-276 CVE-2020-29491: Dell Wyse ThinOS 8.6 and prior versions contain an insecure default configuration vulnerability. A r
Dell Wyse ThinOS 8.6 and prior versions contain an insecure default configuration vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability to gain access to the sensitive information on the local network, leading to the potential compromise of impacted thin clients.
nvd