Home
HIGH: 7.6 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HDefault status
unaffected
Dell ThinOS 2402
affected
Dell ThinOS 2405
affected
Description
Dell ThinOS versions 2402 and 2405, contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Elevation of privileges.
Problem types
CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection')
Product status
Dell ThinOS 2402
Dell ThinOS 2405
Credits
Dell would like to thank REQON for reporting this issue
References
www.dell.com/support/kbdoc/en-us/000228350/dsa-2024-386