Improper Server Validation Vulnerability in Dell Wyse ThinOS
CVE-2021-21532

5MEDIUM

Key Information:

Vendor
Dell
Vendor
CVE Published:
2 April 2021

Summary

The vulnerability in Dell Wyse ThinOS 8.6 MR9 involves improper validation of management server responses. This security flaw can be exploited by attackers to redirect clients to malicious management servers, enabling them to alter device configurations or replace certificate files effectively. This not only jeopardizes the device's security but also poses substantial risks to the integrity of sensitive data.

Affected Version(s)

Wyse Proprietary OS (ThinOS) < unspecified

References

CVSS V3.1

Score:
5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.