Impact
The vulnerability is an improper certificate validation flaw that allows an attacker to bypass protection mechanisms and gain unauthorized access to the device. An unauthenticated attacker who can reach the ThinOS 10 system from an adjacent network can exploit this weakness, potentially compromising the device. The flaw maps to CWE‑295 and can lead to confidentiality and integrity violations if the attacker gains control.
Affected Systems
All Dell ThinOS 10 deployments running a version prior to SecurityAddon_2605.10.2766_T10 are impacted. These include devices hosted by Dell that use the thinOS 10 operating system.
Risk and Exploitability
The CVSS score of 8.3 indicates a high severity. EPSS data is unavailable, so the current exploitation probability is unclear, but the presence of a high severity score indicates a serious risk. The vulnerability is not listed in CISA's KEV catalog, implying no known active exploitation. The likely attack vector is an unauthenticated attacker with network access on the same segment. Exploitation requires no user interaction and could allow the attacker to bypass security controls and access protected resources.
OpenCVE Enrichment