DSA-2024-386: Security Update for Dell ThinOS for a Command Injection Vulnerability

Summary: Dell ThinOS remediation is available for a Command Injection Vulnerability that could be exploited by malicious users to compromise the affected system.

This article applies to This article does not apply to This article is not tied to any specific product. Not all product versions are identified in this article.

Impact

High

Details

Proprietary Code CVEs Description CVSS Base Score CVSS Vector String
CVE-2024-42427 Dell ThinOS versions 2402 and 2405, contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Elevation of privileges. 7.6 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HThis hyperlink is taking you to a website outside of Dell Technologies.
Proprietary Code CVEs Description CVSS Base Score CVSS Vector String
CVE-2024-42427 Dell ThinOS versions 2402 and 2405, contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Elevation of privileges. 7.6 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HThis hyperlink is taking you to a website outside of Dell Technologies.
Dell Technologies recommends all customers consider both the CVSS base score and any relevant temporal and environmental scores that may impact the potential severity associated with a particular security vulnerability.

Affected Products & Remediation

Product

Software/Firmware

Affected Versions

Remediated Versions

Release Date (MM/DD/YYYY)

Link

Latitude 3420

Operating System

Dell ThinOS 2402 and 2405

Dell ThinOS 2408

09/05/2024

ThinOS 9.1.3129 or later to ThinOS 2408 (9.5.3102) Upgrade Image file | Driver Details

Latitude 3440

Operating System

Dell ThinOS 2402 and 2405

Dell ThinOS 2408

09/05/2024

ThinOS 9.1.3129 or later to ThinOS 2408 (9.5.3102) Upgrade Image file | Driver Details

Latitude 5440

Operating System

Dell ThinOS 2402 and 2405

Dell ThinOS 2408

09/05/2024

ThinOS 9.1.3129 or later to ThinOS 2408 (9.5.3102) Upgrade Image file | Driver Details

Latitude 5450

Operating System

Dell ThinOS 2402 and 2405

Dell ThinOS 2408

09/05/2024

ThinOS 9.1.3129 or later to ThinOS 2408 (9.5.3102) Upgrade Image file | Driver Details

OptiPlex 3000 Thin Client

Operating System

Dell ThinOS 2402 and 2405

Dell ThinOS 2408

09/05/2024

ThinOS 9.1.3129 or later to ThinOS 2408 (9.5.3102) Upgrade Image file | Driver Details

OptiPlex 5400 All-in-One

Operating System

Dell ThinOS 2402 and 2405

Dell ThinOS 2408

09/05/2024

ThinOS 9.1.3129 or later to ThinOS 2408 (9.5.3102) Upgrade Image file | Driver Details

OptiPlex AIO 7410

Operating System

Dell ThinOS 2402 and 2405

Dell ThinOS 2408

09/05/2024

ThinOS 9.1.3129 or later to ThinOS 2408 (9.5.3102) Upgrade Image file | Driver Details

OptiPlex AIO 7420

Operating System

Dell ThinOS 2402 and 2405

Dell ThinOS 2408

09/05/2024

ThinOS 9.1.3129 or later to ThinOS 2408 (9.5.3102) Upgrade Image file | Driver Details

Wyse 5070 Thin Client (>=32GB)

Operating System

Dell ThinOS 2402 and 2405

Dell ThinOS 2408

09/05/2024

ThinOS 9.1.3129 or later to ThinOS 2408 (9.5.3102) Upgrade Image file | Driver Details

Wyse 5470 All-in-One Thin Client (>=32GB)

Operating System

Dell ThinOS 2402 and 2405

Dell ThinOS 2408

09/05/2024

ThinOS 9.1.3129 or later to ThinOS 2408 (9.5.3102) Upgrade Image file | Driver Details

Wyse 5470 Mobile Thin Client (>=32GB)

Operating System

Dell ThinOS 2402 and 2405

Dell ThinOS 2408

09/05/2024

ThinOS 9.1.3129 or later to ThinOS 2408 (9.5.3102) Upgrade Image file | Driver Details

 

Product

Software/Firmware

Affected Versions

Remediated Versions

Release Date (MM/DD/YYYY)

Link

Latitude 3420

Operating System

Dell ThinOS 2402 and 2405

Dell ThinOS 2408

09/05/2024

ThinOS 9.1.3129 or later to ThinOS 2408 (9.5.3102) Upgrade Image file | Driver Details

Latitude 3440

Operating System

Dell ThinOS 2402 and 2405

Dell ThinOS 2408

09/05/2024

ThinOS 9.1.3129 or later to ThinOS 2408 (9.5.3102) Upgrade Image file | Driver Details

Latitude 5440

Operating System

Dell ThinOS 2402 and 2405

Dell ThinOS 2408

09/05/2024

ThinOS 9.1.3129 or later to ThinOS 2408 (9.5.3102) Upgrade Image file | Driver Details

Latitude 5450

Operating System

Dell ThinOS 2402 and 2405

Dell ThinOS 2408

09/05/2024

ThinOS 9.1.3129 or later to ThinOS 2408 (9.5.3102) Upgrade Image file | Driver Details

OptiPlex 3000 Thin Client

Operating System

Dell ThinOS 2402 and 2405

Dell ThinOS 2408

09/05/2024

ThinOS 9.1.3129 or later to ThinOS 2408 (9.5.3102) Upgrade Image file | Driver Details

OptiPlex 5400 All-in-One

Operating System

Dell ThinOS 2402 and 2405

Dell ThinOS 2408

09/05/2024

ThinOS 9.1.3129 or later to ThinOS 2408 (9.5.3102) Upgrade Image file | Driver Details

OptiPlex AIO 7410

Operating System

Dell ThinOS 2402 and 2405

Dell ThinOS 2408

09/05/2024

ThinOS 9.1.3129 or later to ThinOS 2408 (9.5.3102) Upgrade Image file | Driver Details

OptiPlex AIO 7420

Operating System

Dell ThinOS 2402 and 2405

Dell ThinOS 2408

09/05/2024

ThinOS 9.1.3129 or later to ThinOS 2408 (9.5.3102) Upgrade Image file | Driver Details

Wyse 5070 Thin Client (>=32GB)

Operating System

Dell ThinOS 2402 and 2405

Dell ThinOS 2408

09/05/2024

ThinOS 9.1.3129 or later to ThinOS 2408 (9.5.3102) Upgrade Image file | Driver Details

Wyse 5470 All-in-One Thin Client (>=32GB)

Operating System

Dell ThinOS 2402 and 2405

Dell ThinOS 2408

09/05/2024

ThinOS 9.1.3129 or later to ThinOS 2408 (9.5.3102) Upgrade Image file | Driver Details

Wyse 5470 Mobile Thin Client (>=32GB)

Operating System

Dell ThinOS 2402 and 2405

Dell ThinOS 2408

09/05/2024

ThinOS 9.1.3129 or later to ThinOS 2408 (9.5.3102) Upgrade Image file | Driver Details

 

Workarounds & Mitigations

None

Revision History

RevisionDateDescription
1.02024-09-09Initial Release
2.02025-02-24Updated Affected Products and Remediation Table:  Updated the product column to add all products affected by the vulnerability
3.02025-02-25Updated Affected Products and Remediation Table:  Updated the Wyse products in table

Acknowledgements

CVE-2024-42427: Dell would like to thank REQON for reporting this issue

Related Information

Affected Products

Latitude 3420, Latitude 3440, Latitude 5440, Latitude 5450, OptiPlex 3000 Thin Client, OptiPlex 5400 All-In-One, OptiPlex All-In-One 7410, OptiPlex All-in-One 7420, Wyse 5070 Thin Client, Wyse 5470 All-In-One, Wyse 5470, Dell ThinOS
Article Properties
Article Number: 000228350
Article Type: Dell Security Advisory
Last Modified: 25 Feb 2025
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.