Impact
Dell ThinOS 10 firmware versions before 2605_10.2616 lack a critical integrity check, a weakness classified as CWE-353, which allows a high privileged attacker with local access to execute arbitrary code. This vulnerability requires local administrative rights and directly compromises the confidentiality and integrity of the device.
Affected Systems
Dell ThinOS 10 firmware versions prior to 2605_10.2616 are affected; newer firmware releases contain the fix and are not vulnerable.
Risk and Exploitability
The CVSS score of 4.4 indicates moderate overall severity, but the local arbitrary code execution capability makes the risk high in environments where local privileged access is possible. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog, implying no known public exploits at this time. The likely attack vector is local privileged access, as local access.
OpenCVE Enrichment