Impact
Dell ThinOS 10 is vulnerable to a missing authentication flaw for a critical function, which can allow an attacker without credentials to manipulate system operations remotely. The weakness is classified as CWE‑306, indicating that authentication checks are insufficient. This flaw can compromise confidentiality and integrity of data controlled by the ThinOS instance, potentially allowing the attacker to execute privileged commands or modify configuration settings. The description confirms that unauthorized access is possible but does not specify whether arbitrary code execution is feasible.
Affected Systems
All Dell ThinOS 10 releases published before SecurityAddon_2605.10.2766_T10 are affected. In particular, any system running a version of ThinOS 10 that has not incorporated the security addon update SecurityAddon_2605.10.2766_T10 or later is vulnerable.
Risk and Exploitability
The CVSS score of 8.6 indicates a high‑severity risk, and the EPSS score is not available, meaning current exploit data is insufficient to estimate spike probability. The vulnerability is not listed in the CISA KEV catalog, which suggests that it has not yet been observed in the wild, but it remains a critical patchable issue. The likely attack vector is remote access over the network, inferred from the description that an unauthenticated attacker can exploit the flaw. An attacker would need the ThinOS system to be reachable and would benefit from any additional local privileges once the critical function is accessed.
OpenCVE Enrichment