Back to overview

CVE-2020-29491

CRITICAL
10.0
CVSS 3.1
Description
Dell Wyse ThinOS 8.6 and prior versions contain an insecure default configuration vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability to gain access to the sensitive information on the local network, leading to the potential compromise of impacted thin clients.

Metadata

CVE ID
CVE-2020-29491
State
PUBLISHED
Assigner
dell
Reserved
2020-12-03 00:00 UTC
Published
2021-01-04 21:15 UTC
Last updated
2024-09-17 03:03 UTC
Primary CWE
CWE-276
CWE-276: Incorrect Default Permissions
Vendor / Product
Dell / Wyse Proprietary OS (ThinOS)
Sources
cve.org  ·  NVD

Severity & Metrics

10.0 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Affected products (1)
VendorProductPlatformVersions
Dell Wyse Proprietary OS (ThinOS) unspecified < 8.6
Weakness (CWE)
CWESourceDescription
CWE-276 cna CWE-276: Incorrect Default Permissions
CVSS scores (1)
ScoreSeverityVersionSourceVector
10.0 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Back to overview