Impact
An Improper Access Control flaw exists in Dell ThinOS 10 devices running versions prior to 2602_10.0765. The flaw allows a low‑privileged attacker who has local access to the device to obtain elevated privileges, effectively gaining administrative control over the ThinOS system. The vulnerability is classified as CWE‑284.
Affected Systems
Dell ThinOS 10, all releases older than 2602_10.0765, are affected. The flaw applies to thin clients running this operating system and does not require any specific configuration beyond standard local access.
Risk and Exploitability
The CVSS score of 7.8 classifies the vulnerability as high severity. Exploitation requires only local access by a low‑privileged user, and public exploits are not known. With EPSS unavailable, the precise likelihood of exploitation remains undetermined. If local access is achieved, the flaw permits escalation to elevated privileges.
OpenCVE Enrichment