PT-2024-29941 · Dell · Dell Thinos

Published

2024-09-10

·

Updated

2024-12-20

·

CVE-2024-42427

CVSS v3.1

7.6

High

VectorAV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Dell ThinOS versions 2402 and 2405
Description The issue is related to an Improper Neutralization of Special Elements used in a Command, also known as a 'Command Injection' vulnerability. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Elevation of privileges.
Recommendations For Dell ThinOS versions 2402 and 2405, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2024-42427

Affected Products

Dell Thinos