Dell ThinOS Command Injection Vulnerability: Unauthorized Elevation of Privileges
CVE-2024-42427
7.6HIGH
Key Information
- Vendor
- Dell
- Status
- Wyse Proprietary Os (modern Thinos)
- Vendor
- CVE Published:
- 10 September 2024
Summary
Dell ThinOS versions 2402 and 2405, contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Elevation of privileges.
Affected Version(s)
Wyse Proprietary OS (Modern ThinOS) = Dell ThinOS 2402
Wyse Proprietary OS (Modern ThinOS) = Dell ThinOS 2405
CVSS V3.1
Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published.
Vulnerability Reserved.
Collectors
NVD DatabaseMitre Database
Credit
Dell would like to thank REQON for reporting this issue