Dell ThinOS 10, versions prior to 2508_10.0127, contain a Protection Mechanism Failure vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Protection mechanism bypass.
The vulnerability results from improper implementation of a protection mechanism (CWE-693) in Dell ThinOS 10. An attacker operating remotely and without any authentication can trigger conditions that cause the bypass of applied system security measures. User interaction (UI:R) is required to carry out the attack, which suggests possible involvement of social engineering elements or operation within the context of a browser or user session. The scope of impact extends beyond the directly attacked component (S:C), which increases potential damage.
Successful exploitation of this vulnerability can lead to complete compromise of system confidentiality, integrity, and availability (C:H/I:H/A:H), including unauthorized access to data and takeover of device control.
Dell ThinOS 10 should be updated as soon as possible to version 2508_10.0127 or later. Detailed update instructions are available in the vendor's security bulletin DSA-2025-331 at: https://www.dell.com/support/kbdoc/en-us/000359619/dsa-2025-331
Dell ThinOS 10 versions prior to 2508_10.0127, installed on devices: Dell Latitude 5440, Dell Latitude 5540, Dell Optiplex Micro Plus 7010, Dell Pro Max 14, Dell Pro Rugged 14 Rb14250.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:HDell Latitude 3330
HWDellall versionsDell Latitude 3420
HWDellall versionsDell Latitude 3440
HWDellall versionsDell Latitude 3450
HWDellall versionsDell Latitude 5440
HWDellall versionsDell Latitude 5450
HWDellall versionsDell Latitude 5520
HWDellall versionsDell Latitude 5530
HWDellall versionsDell Latitude 5540
HWDellall versionsDell Latitude 5550
HWDellall versionsDell Optiplex 3000 Tc
HWDellall versionsDell Optiplex 5400 All In One
HWDellall versionsDell Optiplex 7020
HWDellall versionsDell Optiplex All In One 7410
HWDellall versionsDell Optiplex All In One 7420
HWDellall versionsDell Optiplex Micro Plus 7010
HWDellall versionsDell Precision 3260 Compact
HWDellall versionsDell Precision 3280
HWDellall versionsDell Pro 14 Pc14250
HWDellall versionsDell Pro 16 Pc16250
HWDellall versionsDell Pro 16 Plus Pb16250
HWDellall versionsDell Pro 24 All In One
HWDellall versionsDell Pro Max 14
HWDellall versionsDell Pro Max 16 Plus
HWDellall versionsDell Pro Rugged 13 Ra13250
HWDellall versionsDell Pro Rugged 14 Rb14250
HWDellall versionsDell Pro Slim Low Sff
HWDellall versionsDell Pro Tower Qct1250
HWDellall versionsDell Thinos
OSDell< 2508Dell Wyse 5070 Extended Thin Client
HWDellall versions
Related vulnerabilities
Dell ThinOS 10, versions prior to ThinOS10 2602_10.0765, contain an Improper Access Control vulnerability. A l...
Dell ThinOS 10 versions prior to ThinOS 2602_10.0573, contain an Improper Neutralization of Special Elements u...
Dell Wireless 5932e and Qualcomm Snapdragon X62 Firmware and GNSS/GPS Driver, versions prior to 3.2.0.22 conta...
Dell ThinOS 10, versions prior to 2508_10.0127, contains an Incorrect Permission Assignment for Critical Resou...
Dell ThinOS 10, versions prior to 2508_10.0127, contains an Unverified Ownership vulnerability. A local low-pr...