Dell Wyse ThinOS, versions 9.0, 9.1, and 9.1 MR1, contain a Sensitive Information Disclosure Vulnerability. An authenticated attacker with physical access to the system could exploit this vulnerability to read sensitive Smartcard data in log files.
References
Link | Resource |
---|---|
https://www.dell.com/support/kbdoc/000189543 | Patch Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
History
23 Aug 2021, 17:16
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-532 | |
References | (CONFIRM) https://www.dell.com/support/kbdoc/000189543 - Patch, Vendor Advisory | |
CVSS |
v2 : v3 : |
v2 : 2.1
v3 : 3.9 |
CPE | cpe:2.3:o:dell:wyse_thinos:9.1:*:*:*:*:*:*:* cpe:2.3:h:dell:wyse_5070_thin_client:-:*:*:*:*:*:*:* cpe:2.3:h:dell:wyse_3040_thin_client:-:*:*:*:*:*:*:* cpe:2.3:o:dell:wyse_thinos:9.1:mr1:*:*:*:*:*:* cpe:2.3:o:dell:wyse_thinos:9.0:*:*:*:*:*:*:* cpe:2.3:h:dell:wyse_5470_thin_client:-:*:*:*:*:*:*:* |
10 Aug 2021, 19:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2021-08-10 19:15
Updated : 2024-02-04 21:47
NVD link : CVE-2021-21598
Mitre link : CVE-2021-21598
CVE.ORG link : CVE-2021-21598
JSON object : View
Products Affected
dell
- wyse_3040_thin_client
- wyse_5470_thin_client
- wyse_5070_thin_client
- wyse_thinos
CWE
CWE-532
Insertion of Sensitive Information into Log File