CVE-2024-42427 HIGH

CVE-2024-42427

Vendor Dell
Product Wyse Proprietary OS (Modern ThinOS)
Weakness CWE-77
Published September 10, 2024
Last update September 10, 2024

CVSS base score

7.6/10
Attack vector Physical
Attack complexity Low
Privileges required None
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

What the vulnerability does

01Description

Dell ThinOS versions 2402 and 2405, contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Elevation of privileges.

Key dates

02Disclosure timeline

September 10, 2024 CVE published
September 10, 2024 Record updated