« Volver al listado

CVE-2020-29492

Estado: ModificadaCrítica (10)—

Dell Wyse ThinOS 8.6 and prior versions contain an insecure default configuration vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability to access the writable file and manipulate the configuration of any target specific station.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2020-29492",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.4,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 4.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security_alert@emc.com",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 10,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 6,
        "exploitabilityScore": 3.9
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 10,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.8,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "security_alert@emc.com",
      "affectedData": [
        {
          "vendor": "Dell",
          "product": "Wyse Proprietary OS (ThinOS)",
          "versions": [
            {
              "status": "affected",
              "version": "unspecified",
              "lessThan": "8.6",
              "versionType": "custom"
            }
          ]
        }
      ]
    }
  ],
  "published": "2021-01-04T22:15:13.657",
  "references": [
    {
      "url": "https://www.dell.com/support/kbdoc/en-us/000180768/dsa-2020-281",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security_alert@emc.com"
    },
    {
      "url": "https://www.dell.com/support/kbdoc/en-us/000180768/dsa-2020-281",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security_alert@emc.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-276"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-276"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Dell Wyse ThinOS 8.6 and prior versions contain an insecure default configuration vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability to access the writable file and manipulate the configuration of any target specific station."
    },
    {
      "lang": "es",
      "value": "Dell Wyse ThinOS versiones 8.6 y anteriores, contienen una vulnerabilidad de configuración predeterminada no segura. Un atacante remoto no autenticado podría potencialmente explotar esta vulnerabilidad para acceder al archivo grabable y manipular la configuración de cualquier estación específica objetivo."
    }
  ],
  "lastModified": "2026-06-17T03:11:21.300",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:dell:wyse_thinos:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2F05FD17-BBB4-4FE7-9989-6604A6B1A6DB",
              "versionEndIncluding": "8.6"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:dell:wyse_3040:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "1763236A-8640-400A-A93D-05E3850D9E67"
            },
            {
              "criteria": "cpe:2.3:h:dell:wyse_5010:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "C46AEF9B-52B8-4A32-A89B-E4B309128829"
            },
            {
              "criteria": "cpe:2.3:h:dell:wyse_5040:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "4DF84F29-41D4-47E0-A34A-03D658B2EC85"
            },
            {
              "criteria": "cpe:2.3:h:dell:wyse_5060:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "A366A586-D5B4-4255-83C4-BCF3212B76CD"
            },
            {
              "criteria": "cpe:2.3:h:dell:wyse_5070:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "F53D34DB-897A-430E-B05A-856EF03EC63E"
            },
            {
              "criteria": "cpe:2.3:h:dell:wyse_5470:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "6C5B29FE-A8DC-4F6D-A370-0BB2A921D0B7"
            },
            {
              "criteria": "cpe:2.3:h:dell:wyse_7010:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "D26EFC78-50E1-40E9-A653-9DDC8F248BB3"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "security_alert@emc.com"
}