Dell Wyse Thinos vulnerabilities
10 known vulnerabilities affecting dell/wyse_thinos.
Total CVEs
10
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH2MEDIUM5LOW2
Vulnerabilities
Page 1 of 1
CVE-2024-42427HIGHCVSS 7.6v9.5.1079v9.5.21092024-09-10
CVE-2024-42427 [HIGH] CWE-77 CVE-2024-42427: Dell ThinOS versions 2402 and 2405, contains an Improper Neutralization of Special Elements used in
Dell ThinOS versions 2402 and 2405, contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Elevation of privileges.
nvd
CVE-2023-32447MEDIUMCVSS 5.5fixed in 9.4.21032023-07-20
CVE-2023-32447 [MEDIUM] CWE-312 CVE-2023-32447:
Dell Wyse ThinOS versions prior to 2306 (9.4.2103) contain a sensitive information disclosure vulne
Dell Wyse ThinOS versions prior to 2306 (9.4.2103) contain a sensitive information disclosure vulnerability. A malicious user with local access to the device could exploit this vulnerability to read sensitive information written to the log files.
nvd
CVE-2023-32455MEDIUMCVSS 5.5≤ 9.3.21022023-07-20
CVE-2023-32455 [MEDIUM] CWE-312 CVE-2023-32455:
Dell Wyse ThinOS versions prior to 2208 (9.3.2102) contain a sensitive information disclosure vulne
Dell Wyse ThinOS versions prior to 2208 (9.3.2102) contain a sensitive information disclosure vulnerability. An unauthenticated malicious user with local access to the device could exploit this vulnerability to read sensitive information written to the log files.
nvd
CVE-2023-32446MEDIUMCVSS 5.5v9.4.11412023-07-20
CVE-2023-32446 [MEDIUM] CWE-312 CVE-2023-32446:
Dell Wyse ThinOS versions prior to 2303 (9.4.1141) contain a sensitive information disclosure vulne
Dell Wyse ThinOS versions prior to 2303 (9.4.1141) contain a sensitive information disclosure vulnerability. An unauthenticated malicious user with local access to the device could exploit this vulnerability to read sensitive information written to the log files.
nvd
CVE-2022-34402MEDIUMCVSS 4.9fixed in 9.3.21022022-10-10
CVE-2022-34402 [MEDIUM] CWE-1333 CVE-2022-34402: Dell Wyse ThinOS 2205 contains a Regular Expression Denial of Service Vulnerability in UI. An admin
Dell Wyse ThinOS 2205 contains a Regular Expression Denial of Service Vulnerability in UI. An admin privilege attacker could potentially exploit this vulnerability, leading to denial-of-service.
nvd
CVE-2021-21598LOWCVSS 3.9v9.0v9.1+1 more2021-08-10
CVE-2021-21598 [LOW] CWE-532 CVE-2021-21598: Dell Wyse ThinOS, versions 9.0, 9.1, and 9.1 MR1, contain a Sensitive Information Disclosure Vulnera
Dell Wyse ThinOS, versions 9.0, 9.1, and 9.1 MR1, contain a Sensitive Information Disclosure Vulnerability. An authenticated attacker with physical access to the system could exploit this vulnerability to read sensitive Smartcard data in log files.
nvd
CVE-2021-21597LOWCVSS 3.9v9.0v9.12021-08-10
CVE-2021-21597 [LOW] CWE-532 CVE-2021-21597: Dell Wyse ThinOS, version 9.0, contains a Sensitive Information Disclosure Vulnerability. An authent
Dell Wyse ThinOS, version 9.0, contains a Sensitive Information Disclosure Vulnerability. An authenticated malicious user with physical access to the system could exploit this vulnerability to read sensitive information written to the log files.
nvd
CVE-2021-21532MEDIUMCVSS 6.3fixed in 8.6v8.62021-04-02
CVE-2021-21532 [MEDIUM] CWE-16 CVE-2021-21532: Dell Wyse ThinOS 8.6 MR9 contains remediation for an improper management server validation vulnerabi
Dell Wyse ThinOS 8.6 MR9 contains remediation for an improper management server validation vulnerability that could be potentially exploited to redirect a client to an attacker-controlled management server, thus allowing the attacker to change the device configuration or certificate file.
nvd
CVE-2020-29492CRITICALCVSS 10.0≤ 8.62021-01-04
CVE-2020-29492 [CRITICAL] CWE-276 CVE-2020-29492: Dell Wyse ThinOS 8.6 and prior versions contain an insecure default configuration vulnerability. A r
Dell Wyse ThinOS 8.6 and prior versions contain an insecure default configuration vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability to access the writable file and manipulate the configuration of any target specific station.
nvd
CVE-2020-29491HIGHCVSS 8.6≤ 8.62021-01-04
CVE-2020-29491 [HIGH] CWE-276 CVE-2020-29491: Dell Wyse ThinOS 8.6 and prior versions contain an insecure default configuration vulnerability. A r
Dell Wyse ThinOS 8.6 and prior versions contain an insecure default configuration vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability to gain access to the sensitive information on the local network, leading to the potential compromise of impacted thin clients.
nvd