Description
Dell ThinOS 10, versions prior to ThinOS10 2602_10.0765, contain an Improper Access control vulnerability. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Information exposure.
Problem types
CWE-284: Improper Access Control
Product status
Any version before 2602_10.0765_T10
Credits
Dell would like to thank Darren McDonald from AmberWolf
Dell would like to thank Christophe Schleypen (NATO Cyber Security Centre – NCSC) for reporting this issue.
References
www.dell.com/support/kbdoc/en-us/000463678/dsa-2026-214