DSA-2021-096: Dell Wyse Windows Embedded System Security Update for an Improper Authorization Vulnerability
Zusammenfassung: Dell Wyse Windows Embedded System (WIE10 LTSC 2019) Security update contains remediation for an improper authorization vulnerability.
Dieser Artikel gilt für
Dieser Artikel gilt nicht für
Dieser Artikel ist nicht an ein bestimmtes Produkt gebunden.
In diesem Artikel werden nicht alle Produktversionen aufgeführt.
Auswirkungen
Medium
Details
| Proprietary Code CVE | Description | CVSS Base Score | CVSS Vector String |
| CVE-2021- 21552 | Dell Wyse Windows Embedded System versions WIE10 LTSC 2019 and earlier contain an improper authorization vulnerability. A local authenticated malicious user with low privileges may potentially exploit this vulnerability to bypass the restricted environment and perform unauthorized actions on the affected system. | 5.2 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N |
| Proprietary Code CVE | Description | CVSS Base Score | CVSS Vector String |
| CVE-2021- 21552 | Dell Wyse Windows Embedded System versions WIE10 LTSC 2019 and earlier contain an improper authorization vulnerability. A local authenticated malicious user with low privileges may potentially exploit this vulnerability to bypass the restricted environment and perform unauthorized actions on the affected system. | 5.2 | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N |
Betroffene Produkte und Korrektur
| Product | Affected Versions | Updated Versions | Link to Update | |
|
Dell Wyse 5070 Thin Client |
Versions WIE10 LTSC 2019 and earlier |
Security Update |
|
|
|
Dell Wyse 5470 Thin Client |
Versions WIE10 LTSC 2019 and earlier |
Security Update |
|
|
|
Dell Wyse 5470 All-In-One Thin Client |
Versions WIE10 LTSC 2019 and earlier |
Security Update |
||
| Product | Affected Versions | Updated Versions | Link to Update | |
|
Dell Wyse 5070 Thin Client |
Versions WIE10 LTSC 2019 and earlier |
Security Update |
|
|
|
Dell Wyse 5470 Thin Client |
Versions WIE10 LTSC 2019 and earlier |
Security Update |
|
|
|
Dell Wyse 5470 All-In-One Thin Client |
Versions WIE10 LTSC 2019 and earlier |
Security Update |
||
Revisionsverlauf
| Revision | Date | Description |
| 1.0 | 2021-05-11 | Initial Release |
Danksagung
Dell would like to thank Alessandro Baldini and Alessio D'Anastasio for reporting this issue.
Zugehörige Informationen
Rechtlicher Hinweis
Betroffene Produkte
Product Security Information, Wyse 5070 Thin Client, Wyse 5470 All-In-One, Wyse 5470Artikeleigenschaften
Artikelnummer: 000186134
Artikeltyp: Dell Security Advisory
Zuletzt geändert: 18 Sept. 2025
Antworten auf Ihre Fragen erhalten Sie von anderen Dell NutzerInnen
Support Services
Prüfen Sie, ob Ihr Gerät durch Support Services abgedeckt ist.