MEDIUM · 5.5

CVE-2023-32455

Dell Wyse ThinOS versions prior to 2208 (9.3.2102) contain a sensitive information disclosure vulnerability. An unauthenticated malicious user with local access to the device could exploit this vulne...

Vulnerability Description

Dell Wyse ThinOS versions prior to 2208 (9.3.2102) contain a sensitive information disclosure vulnerability. An unauthenticated malicious user with local access to the device could exploit this vulnerability to read sensitive information written to the log files.

CVSS Score

5.5

MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
DellWyse Thinos<= 9.3.2102
DellLatitude 3420-
DellLatitude 3440-
DellLatitude 5440-
DellOptiplex 3000 Thin Client-
DellOptiplex 5400-
DellWyse 3040 Thin Client-
DellWyse 5070 Thin Client-
DellWyse 5470 All-In-One Thin Client-
DellWyse 5470 Mobile Thin Client-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2023-32455?

CVE-2023-32455 is a vulnerability with a CVSS score of 5.5 (MEDIUM). Dell Wyse ThinOS versions prior to 2208 (9.3.2102) contain a sensitive information disclosure vulnerability. An unauthenticated malicious user with local access to the device could exploit this vulne...

How severe is CVE-2023-32455?

CVE-2023-32455 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2023-32455?

Check the references section above for vendor advisories and patch information. Affected products include: Dell Wyse Thinos, Dell Latitude 3420, Dell Latitude 3440, Dell Latitude 5440, Dell Optiplex 3000 Thin Client.