« Volver al listado

CVE-2020-29491

Estado: ModificadaAlta (8.6)—

Dell Wyse ThinOS 8.6 and prior versions contain an insecure default configuration vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability to gain access to the sensitive information on the local network, leading to the potential compromise of impacted thin clients.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2020-29491",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security_alert@emc.com",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 10,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 6,
        "exploitabilityScore": 3.9
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 8.6,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 4,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "security_alert@emc.com",
      "affectedData": [
        {
          "vendor": "Dell",
          "product": "Wyse Proprietary OS (ThinOS)",
          "versions": [
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "8.6",
              "versionType": "custom"
            }
          ]
        }
      ]
    }
  ],
  "published": "2021-01-04T22:15:13.437",
  "references": [
    {
      "url": "https://www.dell.com/support/kbdoc/en-us/000180768/dsa-2020-281",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security_alert@emc.com"
    },
    {
      "url": "https://www.dell.com/support/kbdoc/en-us/000180768/dsa-2020-281",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security_alert@emc.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-276"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-276"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Dell Wyse ThinOS 8.6 and prior versions contain an insecure default configuration vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability to gain access to the sensitive information on the local network, leading to the potential compromise of impacted thin clients."
    },
    {
      "lang": "es",
      "value": "Dell Wyse ThinOS versiones 8.6 y anteriores, contienen una vulnerabilidad de configuración predeterminada no segura. Un atacante remoto no autenticado podría potencialmente explotar esta vulnerabilidad para obtener acceso a la información confidencial en la red local, conllevando a un potencial compromiso de los clientes ligeros afectados."
    }
  ],
  "lastModified": "2026-06-17T03:11:21.183",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:dell:wyse_thinos:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2F05FD17-BBB4-4FE7-9989-6604A6B1A6DB",
              "versionEndIncluding": "8.6"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:dell:wyse_3040:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "1763236A-8640-400A-A93D-05E3850D9E67"
            },
            {
              "criteria": "cpe:2.3:h:dell:wyse_5010:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "C46AEF9B-52B8-4A32-A89B-E4B309128829"
            },
            {
              "criteria": "cpe:2.3:h:dell:wyse_5040:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "4DF84F29-41D4-47E0-A34A-03D658B2EC85"
            },
            {
              "criteria": "cpe:2.3:h:dell:wyse_5060:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "A366A586-D5B4-4255-83C4-BCF3212B76CD"
            },
            {
              "criteria": "cpe:2.3:h:dell:wyse_5070:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "F53D34DB-897A-430E-B05A-856EF03EC63E"
            },
            {
              "criteria": "cpe:2.3:h:dell:wyse_5470:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "6C5B29FE-A8DC-4F6D-A370-0BB2A921D0B7"
            },
            {
              "criteria": "cpe:2.3:h:dell:wyse_7010:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "D26EFC78-50E1-40E9-A653-9DDC8F248BB3"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "security_alert@emc.com"
}