CRITICAL · 10.0

CVE-2020-29491

Dell Wyse ThinOS 8.6 and prior versions contain an insecure default configuration vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability to gain access to the se...

Vulnerability Description

Dell Wyse ThinOS 8.6 and prior versions contain an insecure default configuration vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability to gain access to the sensitive information on the local network, leading to the potential compromise of impacted thin clients.

CVSS Score

10.0

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
DellWyse Thinos<= 8.6
DellWyse 3040-
DellWyse 5010-
DellWyse 5040-
DellWyse 5060-
DellWyse 5070-
DellWyse 5470-
DellWyse 7010-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-29491?

CVE-2020-29491 is a vulnerability with a CVSS score of 10.0 (CRITICAL). Dell Wyse ThinOS 8.6 and prior versions contain an insecure default configuration vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability to gain access to the se...

How severe is CVE-2020-29491?

CVE-2020-29491 has been rated CRITICAL with a CVSS base score of 10.0/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2020-29491?

Check the references section above for vendor advisories and patch information. Affected products include: Dell Wyse Thinos, Dell Wyse 3040, Dell Wyse 5010, Dell Wyse 5040, Dell Wyse 5060.