PT-2025-11628 · Dell · Dell Thinos
Published
2025-03-18
·
Updated
2025-03-18
·
CVE-2025-27688
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Dell ThinOS versions 2408 and prior
Description
The issue is related to improper permissions, which could be exploited by a low-privileged attacker with local access, potentially leading to elevation of privileges. This is due to incorrect permission assignment for critical resources.
Recommendations
For Dell ThinOS versions 2408 and prior, update to a version later than 2408, such as ThinOS 2502, to resolve the improper permissions vulnerability. As a temporary workaround, consider restricting local access to minimize the risk of exploitation.
Fix
LPE
Incorrect Permission
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dell Thinos