Dell ThinOS 2411 and prior, contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary code execution.
Metrics
Affected Vendors & Products
References
History
Tue, 01 Jul 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Dell
Dell latitude 3420 Dell latitude 3440 Dell latitude 5440 Dell latitude 5450 Dell optiplex 3000 Thin Client Dell optiplex 5400 All-in-one Dell optiplex 7410 All-in-one Dell optiplex 7420 All-in-one Dell thinos Dell wyse 5070 Thin Client Dell wyse 5470 All-in-one Thin Client Dell wyse 5470 Mobile Thin Client |
|
| CPEs | cpe:2.3:h:dell:latitude_3420:-:*:*:*:*:*:*:* cpe:2.3:h:dell:latitude_3440:-:*:*:*:*:*:*:* cpe:2.3:h:dell:latitude_5440:-:*:*:*:*:*:*:* cpe:2.3:h:dell:latitude_5450:-:*:*:*:*:*:*:* cpe:2.3:h:dell:optiplex_3000_thin_client:-:*:*:*:*:*:*:* cpe:2.3:h:dell:optiplex_5400_all-in-one:-:*:*:*:*:*:*:* cpe:2.3:h:dell:optiplex_7410_all-in-one:-:*:*:*:*:*:*:* cpe:2.3:h:dell:optiplex_7420_all-in-one:-:*:*:*:*:*:*:* cpe:2.3:h:dell:wyse_5070_thin_client:-:*:*:*:*:*:*:* cpe:2.3:h:dell:wyse_5470_all-in-one_thin_client:-:*:*:*:*:*:*:* cpe:2.3:h:dell:wyse_5470_mobile_thin_client:-:*:*:*:*:*:*:* cpe:2.3:o:dell:thinos:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Dell
Dell latitude 3420 Dell latitude 3440 Dell latitude 5440 Dell latitude 5450 Dell optiplex 3000 Thin Client Dell optiplex 5400 All-in-one Dell optiplex 7410 All-in-one Dell optiplex 7420 All-in-one Dell thinos Dell wyse 5070 Thin Client Dell wyse 5470 All-in-one Thin Client Dell wyse 5470 Mobile Thin Client |
Fri, 07 Mar 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
ssvc
|
Fri, 07 Mar 2025 08:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Dell ThinOS 2411 and prior, contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary code execution. | |
| Weaknesses | CWE-77 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: dell
Published: 2025-03-07T08:06:12.680Z
Updated: 2025-03-11T03:55:16.832Z
Reserved: 2025-02-07T06:04:04.738Z
Link: CVE-2025-26331
Updated: 2025-03-07T15:19:10.949Z
Status : Analyzed
Published: 2025-03-07T08:15:43.040
Modified: 2025-07-01T15:08:21.283
Link: CVE-2025-26331
No data.