Impact
Dell ThinOS 10 versions older than 2605_10.2100 contain a protection mechanism failure that allows an attacker with physical access to bypass encryption controls and obtain unauthorized access to encrypted data. The vulnerability is classified as CWE-693, representing a flaw in handling of security mechanisms.
Affected Systems
Dell ThinOS 10 is affected, with all releases preceding 2605_10.2100 vulnerable. No other vendors or products are listed.
Risk and Exploitability
The vulnerability has a CVSS score of 6.1, indicating moderate severity. The EPSS score is below 1%, showing a very low likelihood of exploitation at present. It is not catalogued in CISA KEV. Exploitation requires physical access to the device, and no remote exploitation path is documented.
OpenCVE Enrichment