CRITICAL🇵🇱 Wersja polska

CVE-2020-29491

CVSS 10.0v3.1pub. 2021-01-04upd. 2024-11-21

Dell Wyse ThinOS 8.6 and prior versions contain an insecure default configuration vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability to gain access to the sensitive information on the local network, leading to the potential compromise of impacted thin clients.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
  • Dell Wyse 3040

    HW
    Dell
    all versions
  • Dell Wyse 5010

    HW
    Dell
    all versions
  • Dell Wyse 5040

    HW
    Dell
    all versions
  • Dell Wyse 5060

    HW
    Dell
    all versions
  • Dell Wyse 5070

    HW
    Dell
    all versions
  • Dell Wyse 5470

    HW
    Dell
    all versions
  • Dell Wyse 7010

    HW
    Dell
    all versions
  • Dell Wyse Thinos

    OS
    Dell
    ≤ 8.6
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2020-29492CRITICAL10.0PL ✓same product

Dell Wyse ThinOS — niezabezpieczona domyślna konfiguracja umożliwia nieautoryzowany dostęp

CVE-2024-42427HIGH7.6same product

Dell ThinOS versions 2402 and 2405, contains an Improper Neutralization of Special Elements used in a Command ...

CVE-2024-22429HIGH7.5same product

Dell BIOS contains an Improper Input Validation vulnerability. A local authenticated malicious user with admin...

CVE-2021-21597HIGH7.2same product

Dell Wyse ThinOS, version 9.0, contains a Sensitive Information Disclosure Vulnerability. An authenticated mal...

CVE-2023-32447MEDIUM5.5same product

Dell Wyse ThinOS versions prior to 2306 (9.4.2103) contain a sensitive information disclosure vulnerability. ...