10

CVE-2020-29492

Dell Wyse ThinOS 8.6 and prior versions contain an insecure default configuration vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability to access the writable file and manipulate the configuration of any target specific station.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Dell ≫ Wyse Thinos Version <= 8.6
   Dell ≫ Wyse 3040 Version -
   Dell ≫ Wyse 5010 Version -
   Dell ≫ Wyse 5040 Version -
   Dell ≫ Wyse 5060 Version -
   Dell ≫ Wyse 5070 Version -
   Dell ≫ Wyse 5470 Version -
   Dell ≫ Wyse 7010 Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.74% 0.747
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 10 3.9 5.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
NIST 6.4 10 4.9
AV:N/AC:L/Au:N/C:P/I:P/A:N
EMC 10 3.9 6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CWE-276 Incorrect Default Permissions

During installation, installed file permissions are set to allow anyone to modify those files.

https://www.dell.com/support/kbdoc/en-us/000180768/dsa-2020-281
Vendor Advisory