Impact
Dell ThinOS 10 contains an Improper Access Control flaw that allows a user with low privileges and local access to gain unauthorized access to the system. The vulnerability can be leveraged to bypass intended access restrictions, potentially enabling a user to execute privileged commands or read sensitive data without proper authorization. This impact affects the confidentiality and integrity of the system as the attacker may manipulate or retrieve protected information.
Affected Systems
The affected product is Dell ThinOS 10, specifically all releases prior to version 2605_10.2518. Only these older builds are vulnerable; later releases contain the fix.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting that exploitation may not yet be widespread. The attack vector described is a low‑privileged local attacker, implying the attacker must have physical or local network access to the device. Once the flaw is triggered, the attacker can gain unauthorized control within the scope of the compromised system.
OpenCVE Enrichment