Impact
The vulnerability is an obsolete feature in the user interface of Dell ThinOS 10. A locally connected attacker with only low privileges can exploit this flaw, potentially gaining unauthorized access. The primary consequence is unapproved use of system resources beyond the attacker’s authorized privileges.
Affected Systems
Dell ThinOS 10, versions earlier than 2605_10.2100, are affected. This includes all installations of ThinOS 10 prior to the release identified by the reference advisory.
Risk and Exploitability
With a CVSS score of 7.8, the vulnerability is considered high severity. The EPSS score of less than 1% indicates that the probability of exploitation is currently very low, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local, requiring physical or privileged network access. Given the low exploitation probability but substantial impact, systems should still be updated promptly to mitigate the risk.
OpenCVE Enrichment