CRITICAL🇵🇱 Wersja polska

CVE-2025-43728

CVSS 9.6v3.1pub. 2025-08-27upd. 2026-01-15

Dell ThinOS 10, versions prior to 2508_10.0127, contain a Protection Mechanism Failure vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Protection mechanism bypass.

🤖 AI Analysis
How it works

The vulnerability results from improper implementation of a protection mechanism (CWE-693) in Dell ThinOS 10. An attacker operating remotely and without any authentication can trigger conditions that cause the bypass of applied system security measures. User interaction (UI:R) is required to carry out the attack, which suggests possible involvement of social engineering elements or operation within the context of a browser or user session. The scope of impact extends beyond the directly attacked component (S:C), which increases potential damage.

Impact

Successful exploitation of this vulnerability can lead to complete compromise of system confidentiality, integrity, and availability (C:H/I:H/A:H), including unauthorized access to data and takeover of device control.

Mitigation & patch

Dell ThinOS 10 should be updated as soon as possible to version 2508_10.0127 or later. Detailed update instructions are available in the vendor's security bulletin DSA-2025-331 at: https://www.dell.com/support/kbdoc/en-us/000359619/dsa-2025-331

Who is affected

Dell ThinOS 10 versions prior to 2508_10.0127, installed on devices: Dell Latitude 5440, Dell Latitude 5540, Dell Optiplex Micro Plus 7010, Dell Pro Max 14, Dell Pro Rugged 14 Rb14250.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
  • Dell Latitude 3330

    HW
    Dell
    all versions
  • Dell Latitude 3420

    HW
    Dell
    all versions
  • Dell Latitude 3440

    HW
    Dell
    all versions
  • Dell Latitude 3450

    HW
    Dell
    all versions
  • Dell Latitude 5440

    HW
    Dell
    all versions
  • Dell Latitude 5450

    HW
    Dell
    all versions
  • Dell Latitude 5520

    HW
    Dell
    all versions
  • Dell Latitude 5530

    HW
    Dell
    all versions
  • Dell Latitude 5540

    HW
    Dell
    all versions
  • Dell Latitude 5550

    HW
    Dell
    all versions
  • Dell Optiplex 3000 Tc

    HW
    Dell
    all versions
  • Dell Optiplex 5400 All In One

    HW
    Dell
    all versions
  • Dell Optiplex 7020

    HW
    Dell
    all versions
  • Dell Optiplex All In One 7410

    HW
    Dell
    all versions
  • Dell Optiplex All In One 7420

    HW
    Dell
    all versions
  • Dell Optiplex Micro Plus 7010

    HW
    Dell
    all versions
  • Dell Precision 3260 Compact

    HW
    Dell
    all versions
  • Dell Precision 3280

    HW
    Dell
    all versions
  • Dell Pro 14 Pc14250

    HW
    Dell
    all versions
  • Dell Pro 16 Pc16250

    HW
    Dell
    all versions
  • Dell Pro 16 Plus Pb16250

    HW
    Dell
    all versions
  • Dell Pro 24 All In One

    HW
    Dell
    all versions
  • Dell Pro Max 14

    HW
    Dell
    all versions
  • Dell Pro Max 16 Plus

    HW
    Dell
    all versions
  • Dell Pro Rugged 13 Ra13250

    HW
    Dell
    all versions
  • Dell Pro Rugged 14 Rb14250

    HW
    Dell
    all versions
  • Dell Pro Slim Low Sff

    HW
    Dell
    all versions
  • Dell Pro Tower Qct1250

    HW
    Dell
    all versions
  • Dell Thinos

    OS
    Dell
    < 2508
  • Dell Wyse 5070 Extended Thin Client

    HW
    Dell
    all versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2026-40715HIGH7.8same product

Dell ThinOS 10, versions prior to ThinOS10 2602_10.0765, contain an Improper Access Control vulnerability. A l...

CVE-2026-23862HIGH7.8same product

Dell ThinOS 10 versions prior to ThinOS 2602_10.0573, contain an Improper Neutralization of Special Elements u...

CVE-2025-43993HIGH7.8same product

Dell Wireless 5932e and Qualcomm Snapdragon X62 Firmware and GNSS/GPS Driver, versions prior to 3.2.0.22 conta...

CVE-2025-43729HIGH7.8same product

Dell ThinOS 10, versions prior to 2508_10.0127, contains an Incorrect Permission Assignment for Critical Resou...

CVE-2025-43882HIGH7.8same product

Dell ThinOS 10, versions prior to 2508_10.0127, contains an Unverified Ownership vulnerability. A local low-pr...