3.9
CVE-2021-21598
- EPSS 0.06%
- Veröffentlicht 10.08.2021 19:15:07
- Zuletzt bearbeitet 21.11.2024 05:48:40
- Quelle security_alert@emc.com
- CVE-Watchlists
- Unerledigt
Dell Wyse ThinOS, versions 9.0, 9.1, and 9.1 MR1, contain a Sensitive Information Disclosure Vulnerability. An authenticated attacker with physical access to the system could exploit this vulnerability to read sensitive Smartcard data in log files.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Dell ≫ Wyse Thinos Version9.0
Dell ≫ Wyse 3040 Thin Client Version-
Dell ≫ Wyse 5070 Thin Client Version-
Dell ≫ Wyse 5470 Thin Client Version-
Dell ≫ Wyse 5070 Thin Client Version-
Dell ≫ Wyse 5470 Thin Client Version-
Dell ≫ Wyse Thinos Version9.1
Dell ≫ Wyse 3040 Thin Client Version-
Dell ≫ Wyse 5070 Thin Client Version-
Dell ≫ Wyse 5470 Thin Client Version-
Dell ≫ Wyse 5070 Thin Client Version-
Dell ≫ Wyse 5470 Thin Client Version-
Dell ≫ Wyse Thinos Version9.1 Updatemr1
Dell ≫ Wyse 3040 Thin Client Version-
Dell ≫ Wyse 5070 Thin Client Version-
Dell ≫ Wyse 5470 Thin Client Version-
Dell ≫ Wyse 5070 Thin Client Version-
Dell ≫ Wyse 5470 Thin Client Version-
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.06% | 0.18 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 3.9 | 0.3 | 3.6 |
CVSS:3.1/AV:P/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
|
| nvd@nist.gov | 2.1 | 3.9 | 2.9 |
AV:L/AC:L/Au:N/C:P/I:N/A:N
|
| security_alert@emc.com | 3.9 | 0.3 | 3.6 |
CVSS:3.1/AV:P/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
|
CWE-532 Insertion of Sensitive Information into Log File
The product writes sensitive information to a log file.