3.9

CVE-2021-21597

Dell Wyse ThinOS, version 9.0, contains a Sensitive Information Disclosure Vulnerability. An authenticated malicious user with physical access to the system could exploit this vulnerability to read sensitive information written to the log files.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Dell ≫ Wyse Thinos Version 9.0
   Dell ≫ Wyse 3040 Thin Client Version -
   Dell ≫ Wyse 5070 Thin Client Version -
   Dell ≫ Wyse 5470 Thin Client Version -
Dell ≫ Wyse Thinos Version 9.1
   Dell ≫ Wyse 3040 Thin Client Version -
   Dell ≫ Wyse 5070 Thin Client Version -
   Dell ≫ Wyse 5470 Thin Client Version -
Dell ≫ Wyse Thinos Version 9.1 Update mr1
   Dell ≫ Wyse 3040 Thin Client Version -
   Dell ≫ Wyse 5070 Thin Client Version -
   Dell ≫ Wyse 5470 Thin Client Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.25% 0.161
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 3.9 0.3 3.6
CVSS:3.1/AV:P/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
NIST 2.1 3.9 2.9
AV:L/AC:L/Au:N/C:P/I:N/A:N
EMC 7.2 0.5 6
CVSS:3.1/AV:P/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
CWE-532 Insertion of Sensitive Information into Log File

The product writes sensitive information to a log file.

https://www.dell.com/support/kbdoc/000189543
Patch
Vendor Advisory