Description
Dell ThinOS 10, versions prior to 2605_10.2100 contain a Protection Mechanism Failure vulnerability. An attacker with physical access could potentially exploit this vulnerability, leading to unauthorized access to encrypted data.
Published: 2026-07-15
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Dell ThinOS 10 versions older than 2605_10.2100 contain a protection mechanism failure that allows an attacker with physical access to bypass encryption controls and obtain unauthorized access to encrypted data. The vulnerability is classified as CWE-693, representing a flaw in handling of security mechanisms.

Affected Systems

Dell ThinOS 10 is affected, with all releases preceding 2605_10.2100 vulnerable. No other vendors or products are listed.

Risk and Exploitability

The vulnerability has a CVSS score of 6.1, indicating moderate severity. The EPSS score is below 1%, showing a very low likelihood of exploitation at present. It is not catalogued in CISA KEV. Exploitation requires physical access to the device, and no remote exploitation path is documented.

Generated by OpenCVE AI on August 1, 2026 at 08:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update ThinOS to version 2605_10.2100.
  • Enforce stringent physical security controls to restrict unauthorized physical access to devices running ThinOS 10.
  • Monitor and audit device access and tampering to detect and respond to physical intrusion attempts promptly.

Generated by OpenCVE AI on August 1, 2026 at 08:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 01 Aug 2026 09:15:00 +0000

Type Values Removed Values Added
Title Protection Mechanism Failure in Dell ThinOS 10 Enabling Unauthorized Access via Physical Interface

Thu, 30 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell thinos
Vendors & Products Dell
Dell thinos

Wed, 29 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
Title Physical Access Protection Mechanism Failure Enables Unauthorized Encrypted Data Access

Sun, 26 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
Title Physical Access Protection Mechanism Failure Enables Unauthorized Encrypted Data Access

Wed, 22 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Title Protection Mechanism Failure in Dell ThinOS 10 Enabling Unauthorized Access to Encrypted Data via Physical Access

Fri, 17 Jul 2026 05:15:00 +0000

Type Values Removed Values Added
Title Protection Mechanism Failure in Dell ThinOS 10 Enabling Unauthorized Access to Encrypted Data via Physical Access

Wed, 15 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 15 Jul 2026 18:00:00 +0000

Type Values Removed Values Added
Description Dell ThinOS 10, versions prior to 2605_10.2100 contain a Protection Mechanism Failure vulnerability. An attacker with physical access could potentially exploit this vulnerability, leading to unauthorized access to encrypted data.
Weaknesses CWE-693
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-07-15T19:30:38.769Z

Reserved: 2026-06-18T17:04:56.016Z

Link: CVE-2026-56087

cve-icon Vulnrichment

Updated: 2026-07-15T19:30:33.855Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T09:00:04Z

Weaknesses
  • CWE-693

    Protection Mechanism Failure