PT-2025-11628 · Dell · Dell Thinos
Publicado
2025-03-18
·
Atualizado
2025-03-18
·
CVE-2025-27688
CVSS v3.1
7.8
Alta
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Dell ThinOS versions 2408 and prior
Description
The issue is related to improper permissions, which could be exploited by a low-privileged attacker with local access, potentially leading to elevation of privileges. This is due to incorrect permission assignment for critical resources.
Recommendations
For Dell ThinOS versions 2408 and prior, update to a version later than 2408, such as ThinOS 2502, to resolve the improper permissions vulnerability. As a temporary workaround, consider restricting local access to minimize the risk of exploitation.
Correção
LPE
Incorrect Permission
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Dell Thinos