Dell Wyse ThinOS versions prior to 2306 (9.4.2103) contain a sensitive information disclosure vulnerability. A malicious user with local access to the device could exploit this vulnerability to read sensitive information written to the log files.
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NDell Latitude 3420
HWDellall versionsDell Latitude 3440
HWDellall versionsDell Latitude 5440
HWDellall versionsDell Optiplex 3000 Thin Client
HWDellall versionsDell Optiplex 5400
HWDellall versionsDell Wyse 3040 Thin Client
HWDellall versionsDell Wyse 5070 Thin Client
HWDellall versionsDell Wyse 5470 All In One Thin Client
HWDellall versionsDell Wyse 5470 Mobile Thin Client
HWDellall versionsDell Wyse Thinos
OSDell< 9.4.2103
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Related vulnerabilities
CVE-2025-43728CRITICAL9.6PL ✓same product
Obejście mechanizmu ochrony w Dell ThinOS 10 (Auth Bypass)
CVE-2020-29491CRITICAL10.0PL ✓same product
Dell Wyse ThinOS — niebezpieczna domyślna konfiguracja umożliwia nieautoryzowany dostęp
CVE-2020-29492CRITICAL10.0PL ✓same product
Dell Wyse ThinOS — niezabezpieczona domyślna konfiguracja umożliwia nieautoryzowany dostęp
CVE-2025-43729HIGH7.8same product
Dell ThinOS 10, versions prior to 2508_10.0127, contains an Incorrect Permission Assignment for Critical Resou...
CVE-2025-43730HIGH8.4same product
Dell ThinOS 10, versions prior to 2508_10.0127, contains an Improper Neutralization of Argument Delimiters in ...