CVE-2024-42427

Severity CVSS v4.0:
Pending analysis
Type:
CWE-77 Command Injection
Publication date:
10/09/2024
Last modified:
20/12/2024

Description

Dell ThinOS versions 2402 and 2405, contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Elevation of privileges.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:dell:wyse_thinos:9.5.1079:*:*:*:*:*:*:*
cpe:2.3:o:dell:wyse_thinos:9.5.2109:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools