MEDIUM🇵🇱 Wersja polska

CVE-2023-32455

CVSS 5.5v3.1pub. 2023-07-20upd. 2024-11-21

Dell Wyse ThinOS versions prior to 2208 (9.3.2102) contain a sensitive information disclosure vulnerability. An unauthenticated malicious user with local access to the device could exploit this vulnerability to read sensitive information written to the log files.

CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
  • Dell Latitude 3420

    HW
    Dell
    all versions
  • Dell Latitude 3440

    HW
    Dell
    all versions
  • Dell Latitude 5440

    HW
    Dell
    all versions
  • Dell Optiplex 3000 Thin Client

    HW
    Dell
    all versions
  • Dell Optiplex 5400

    HW
    Dell
    all versions
  • Dell Wyse 3040 Thin Client

    HW
    Dell
    all versions
  • Dell Wyse 5070 Thin Client

    HW
    Dell
    all versions
  • Dell Wyse 5470 All In One Thin Client

    HW
    Dell
    all versions
  • Dell Wyse 5470 Mobile Thin Client

    HW
    Dell
    all versions
  • Dell Wyse Thinos

    OS
    Dell
    ≤ 9.3.2102
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2025-43728CRITICAL9.6PL ✓same product

Obejście mechanizmu ochrony w Dell ThinOS 10 (Auth Bypass)

CVE-2020-29491CRITICAL10.0PL ✓same product

Dell Wyse ThinOS — niebezpieczna domyślna konfiguracja umożliwia nieautoryzowany dostęp

CVE-2020-29492CRITICAL10.0PL ✓same product

Dell Wyse ThinOS — niezabezpieczona domyślna konfiguracja umożliwia nieautoryzowany dostęp

CVE-2025-43729HIGH7.8same product

Dell ThinOS 10, versions prior to 2508_10.0127, contains an Incorrect Permission Assignment for Critical Resou...

CVE-2025-43730HIGH8.4same product

Dell ThinOS 10, versions prior to 2508_10.0127, contains an Improper Neutralization of Argument Delimiters in ...