Back to overview

CVE-2020-29492

CRITICAL
10.0
CVSS 3.1
Description
Dell Wyse ThinOS 8.6 and prior versions contain an insecure default configuration vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability to access the writable file and manipulate the configuration of any target specific station.

Metadata

CVE ID
CVE-2020-29492
State
PUBLISHED
Assigner
dell
Reserved
2020-12-03 00:00 UTC
Published
2021-01-04 21:15 UTC
Last updated
2024-09-16 20:17 UTC
Primary CWE
CWE-276
CWE-276: Incorrect Default Permissions
Vendor / Product
Dell / Wyse Proprietary OS (ThinOS)
Sources
cve.org  ·  NVD

Severity & Metrics

10.0 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Affected products (1)
VendorProductPlatformVersions
Dell Wyse Proprietary OS (ThinOS) unspecified < 8.6
Weakness (CWE)
CWESourceDescription
CWE-276 cna CWE-276: Incorrect Default Permissions
CVSS scores (1)
ScoreSeverityVersionSourceVector
10.0 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Back to overview