Impact
Dell ThinOS 10 releases prior to build 2605_10.2616 contain a flaw that allows a low‑privileged user with physical access to downgrade the security version number. This manipulation can bypass protection mechanisms and is an example of CWE‑1328.
Affected Systems
This vulnerability affects Dell ThinOS 10 in all versions before build 2605_10.2616. The affected vendor is Dell and the product is ThinOS 10.
Risk and Exploitability
The CVSS score is 6.6, indicating moderate severity. No EPSS score is publicly available, and the vulnerability is not listed in CISA KEV. Because the condition requires proximity to the device, the exploitation risk is limited to environments where the device is physically accessible.
OpenCVE Enrichment