Impact
Dell ThinOS 10 contains a Protection Mechanism Failure (CWE-284) that enables an unauthenticated attacker with remote access to potentially attain arbitrary code execution inside the ThinOS application context. The flaw bypasses normal protective controls, allowing malicious code to run with the privileges of the ThinOS process, threatening confidentiality and integrity of the system.
Affected Systems
All Dell ThinOS 10 releases older than 2605_10.2616 are affected. No other vendors or product lines are listed in the current advisory.
Risk and Exploitability
The CVSS score of 9.4 denotes a critical severity and indicates that environment. Because the EPSS score is not available and the vulnerability exact likelihood of exploitation is uncertain, yet the combination of remote unauthenticated access and high exploit if the ThinOS management interfaces are reachable. It is inferred that the ThinOS management interfaces are a likely attack surface, though this is not explicitly confirmed in the advisory.
OpenCVE Enrichment