5.5

CVE-2023-32447

Dell Wyse ThinOS versions prior to 2306 (9.4.2103) contain a sensitive information disclosure vulnerability. A malicious user with local access to the device could exploit this vulnerability to read sensitive information written to the log files.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Dell ≫ Wyse Thinos Version < 9.4.2103
   Dell ≫ Latitude 3420 Version -
   Dell ≫ Latitude 3440 Version -
   Dell ≫ Latitude 5440 Version -
   Dell ≫ Optiplex 3000 Thin Client Version -
   Dell ≫ Optiplex 5400 Version -
   Dell ≫ Wyse 3040 Thin Client Version -
   Dell ≫ Wyse 5070 Thin Client Version -
   Dell ≫ Wyse 5470 All-in-one Thin Client Version -
   Dell ≫ Wyse 5470 Mobile Thin Client Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.12% 0.023
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EMC 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CWE-312 Cleartext Storage of Sensitive Information

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

CWE-532 Insertion of Sensitive Information into Log File

The product writes sensitive information to a log file.

https://www.dell.com/support/kbdoc/en-us/000215864/dsa-2023-247
Vendor Advisory