8.8
CVE-2021-21552
- EPSS 0.14%
- Veröffentlicht 21.05.2021 20:15:07
- Zuletzt bearbeitet 21.11.2024 05:48:34
- Quelle security_alert@emc.com
- CVE-Watchlists
- Unerledigt
Dell Wyse Windows Embedded System versions WIE10 LTSC 2019 and earlier contain an improper authorization vulnerability. A local authenticated malicious user with low privileges may potentially exploit this vulnerability to bypass the restricted environment and perform unauthorized actions on the affected system.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Windows 10 SwEditionenterprise_ltsc Version <= 2019
Dell ≫ Wyse 5070 Thin Client Version-
Dell ≫ Wyse 5470 All-in-one Thin Client Version-
Dell ≫ Wyse 5470 Thin Client Version-
Dell ≫ Wyse 5470 All-in-one Thin Client Version-
Dell ≫ Wyse 5470 Thin Client Version-
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.14% | 0.347 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 8.8 | 2 | 6 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
|
| nvd@nist.gov | 7.2 | 3.9 | 10 |
AV:L/AC:L/Au:N/C:C/I:C/A:C
|
| security_alert@emc.com | 5.2 | 2 | 2.7 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
|
CWE-863 Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.