Impact
Dell ThinOS 10 versions prior to 2605_10.2616 contain a Download of Code Without Integrity Check vulnerability. An unauthenticated attacker who has physical access may exploit this flaw, leading to arbitrary code execution on the affected device. The weakness (CWE‑494) permits execution of malicious code without verifying its integrity, compromising confidentiality, integrity, and availability of the system.
Affected Systems
Dell ThinOS 10, versions before 2605_10.2616
Risk and Exploitability
The CVSS score of 6.8 indicates moderate severity. EPSS data is not available, so the current exploitation probability is uncertain. The vulnerability is not listed in the CISA KEV catalog, suggesting no widespread active exploitation yet. Because the attack requires physical access and unauthenticated use, the primary vector is local; attackers would need to physically hand a removable medium or similar to trigger the download and execution.
OpenCVE Enrichment