7.8

CVE-2025-27688

Dell ThinOS 2408 and prior, contains an improper permissions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
DellThinos Version <= 2408
   DellLatitude 3420 Version-
   DellLatitude 3440 Version-
   DellLatitude 5440 Version-
   DellLatitude 5450 Version-
   DellOptiplex 3000 Thin Client Version-
   DellOptiplex 5400 All-in-one Version-
   DellOptiplex 7410 All-in-one Version-
   DellOptiplex 7420 All-in-one Version-
   DellWyse 5070 Thin Client Version-
   DellWyse 5470 All-in-one Thin Client Version-
   DellWyse 5470 Mobile Thin Client Version-
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.08% 0.242
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
security_alert@emc.com 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-732 Incorrect Permission Assignment for Critical Resource

The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.