Show filters
10 Total Results
Displaying 1-10 of 10
Sort by:
Attacker Value
Unknown

CVE-2024-42427

Disclosure Date: September 10, 2024 (last updated December 21, 2024)
Dell ThinOS versions 2402 and 2405, contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Elevation of privileges.
Attacker Value
Unknown

CVE-2023-32455

Disclosure Date: July 20, 2023 (last updated October 08, 2023)
Dell Wyse ThinOS versions prior to 2208 (9.3.2102) contain a sensitive information disclosure vulnerability. An unauthenticated malicious user with local access to the device could exploit this vulnerability to read sensitive information written to the log files.
Attacker Value
Unknown

CVE-2023-32447

Disclosure Date: July 20, 2023 (last updated October 08, 2023)
Dell Wyse ThinOS versions prior to 2306 (9.4.2103) contain a sensitive information disclosure vulnerability. A malicious user with local access to the device could exploit this vulnerability to read sensitive information written to the log files.
Attacker Value
Unknown

CVE-2023-32446

Disclosure Date: July 20, 2023 (last updated October 08, 2023)
Dell Wyse ThinOS versions prior to 2303 (9.4.1141) contain a sensitive information disclosure vulnerability. An unauthenticated malicious user with local access to the device could exploit this vulnerability to read sensitive information written to the log files.
Attacker Value
Unknown

CVE-2022-34402

Disclosure Date: September 14, 2022 (last updated October 08, 2023)
Dell Wyse ThinOS 2205 contains a Regular Expression Denial of Service Vulnerability in UI. An admin privilege attacker could potentially exploit this vulnerability, leading to denial-of-service.
Attacker Value
Unknown

CVE-2021-21598

Disclosure Date: July 21, 2021 (last updated February 23, 2025)
Dell Wyse ThinOS, versions 9.0, 9.1, and 9.1 MR1, contain a Sensitive Information Disclosure Vulnerability. An authenticated attacker with physical access to the system could exploit this vulnerability to read sensitive Smartcard data in log files.
Attacker Value
Unknown

CVE-2021-21597

Disclosure Date: July 21, 2021 (last updated February 23, 2025)
Dell Wyse ThinOS, version 9.0, contains a Sensitive Information Disclosure Vulnerability. An authenticated malicious user with physical access to the system could exploit this vulnerability to read sensitive information written to the log files.
Attacker Value
Unknown

CVE-2021-21532

Disclosure Date: March 31, 2021 (last updated February 22, 2025)
Dell Wyse ThinOS 8.6 MR9 contains remediation for an improper management server validation vulnerability that could be potentially exploited to redirect a client to an attacker-controlled management server, thus allowing the attacker to change the device configuration or certificate file.
Attacker Value
Unknown

CVE-2020-29491

Disclosure Date: December 21, 2020 (last updated February 22, 2025)
Dell Wyse ThinOS 8.6 and prior versions contain an insecure default configuration vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability to gain access to the sensitive information on the local network, leading to the potential compromise of impacted thin clients.
Attacker Value
Unknown

CVE-2020-29492

Disclosure Date: December 21, 2020 (last updated February 22, 2025)
Dell Wyse ThinOS 8.6 and prior versions contain an insecure default configuration vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability to access the writable file and manipulate the configuration of any target specific station.