PT-2021-14582 · Dell · Dell Wyse Thinos
Emanuel Rodrigues
·
Published
2021-04-02
·
Updated
2022-10-24
·
CVE-2021-21532
CVSS v3.1
6.3
Medium
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Dell Wyse ThinOS versions prior to 8.6 MR9
Description
The issue is related to an improper management server validation that could be exploited to redirect a client to an attacker-controlled management server. This could allow the attacker to change the device configuration or certificate file.
Recommendations
For versions prior to 8.6 MR9, update to version 8.6 MR9 to resolve the issue.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Dell Wyse Thinos