5.5

CVE-2023-32455

Dell Wyse ThinOS versions prior to 2208 (9.3.2102) contain a sensitive information disclosure vulnerability. An unauthenticated malicious user with local access to the device could exploit this vulnerability to read sensitive information written to the log files.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Dell ≫ Wyse Thinos Version <= 9.3.2102
   Dell ≫ Latitude 3420 Version -
   Dell ≫ Latitude 3440 Version -
   Dell ≫ Latitude 5440 Version -
   Dell ≫ Optiplex 3000 Thin Client Version -
   Dell ≫ Optiplex 5400 Version -
   Dell ≫ Wyse 3040 Thin Client Version -
   Dell ≫ Wyse 5070 Thin Client Version -
   Dell ≫ Wyse 5470 All-in-one Thin Client Version -
   Dell ≫ Wyse 5470 Mobile Thin Client Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.12% 0.023
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EMC 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CWE-312 Cleartext Storage of Sensitive Information

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

CWE-532 Insertion of Sensitive Information into Log File

The product writes sensitive information to a log file.

https://www.dell.com/support/kbdoc/en-us/000215864/dsa-2023-247
Vendor Advisory