7.2

CVE-2021-21597

Dell Wyse ThinOS, version 9.0, contains a Sensitive Information Disclosure Vulnerability. An authenticated malicious user with physical access to the system could exploit this vulnerability to read sensitive information written to the log files.

Data is provided by the National Vulnerability Database (NVD)
DellWyse Thinos Version9.0
   DellWyse 3040 Thin Client Version-
   DellWyse 5070 Thin Client Version-
   DellWyse 5470 Thin Client Version-
DellWyse Thinos Version9.1
   DellWyse 3040 Thin Client Version-
   DellWyse 5070 Thin Client Version-
   DellWyse 5470 Thin Client Version-
DellWyse Thinos Version9.1 Updatemr1
   DellWyse 3040 Thin Client Version-
   DellWyse 5070 Thin Client Version-
   DellWyse 5470 Thin Client Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.04% 0.122
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 3.9 0.3 3.6
CVSS:3.1/AV:P/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
nvd@nist.gov 2.1 3.9 2.9
AV:L/AC:L/Au:N/C:P/I:N/A:N
security_alert@emc.com 7.2 0.5 6
CVSS:3.1/AV:P/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
CWE-532 Insertion of Sensitive Information into Log File

The product writes sensitive information to a log file.