DSA-2024-386: Security Update for Dell ThinOS for a Command Injection Vulnerability
Summary: Dell ThinOS remediation is available for a Command Injection Vulnerability that could be exploited by malicious users to compromise the affected system.
Impact
High
Details
| Proprietary Code CVEs | Description | CVSS Base Score | CVSS Vector String |
|---|---|---|---|
| CVE-2024-42427 | Dell ThinOS versions 2402 and 2405, contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Elevation of privileges. | 7.6 | CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
| Proprietary Code CVEs | Description | CVSS Base Score | CVSS Vector String |
|---|---|---|---|
| CVE-2024-42427 | Dell ThinOS versions 2402 and 2405, contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Elevation of privileges. | 7.6 | CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Affected Products & Remediation
|
Product |
Software/Firmware |
Affected Versions |
Remediated Versions |
Release Date (MM/DD/YYYY) |
Link |
|
Latitude 3420 |
Operating System |
Dell ThinOS 2402 and 2405 |
Dell ThinOS 2408 |
09/05/2024 |
ThinOS 9.1.3129 or later to ThinOS 2408 (9.5.3102) Upgrade Image file | Driver Details |
|
Latitude 3440 |
Operating System |
Dell ThinOS 2402 and 2405 |
Dell ThinOS 2408 |
09/05/2024 |
ThinOS 9.1.3129 or later to ThinOS 2408 (9.5.3102) Upgrade Image file | Driver Details |
|
Latitude 5440 |
Operating System |
Dell ThinOS 2402 and 2405 |
Dell ThinOS 2408 |
09/05/2024 |
ThinOS 9.1.3129 or later to ThinOS 2408 (9.5.3102) Upgrade Image file | Driver Details |
|
Latitude 5450 |
Operating System |
Dell ThinOS 2402 and 2405 |
Dell ThinOS 2408 |
09/05/2024 |
ThinOS 9.1.3129 or later to ThinOS 2408 (9.5.3102) Upgrade Image file | Driver Details |
|
OptiPlex 3000 Thin Client |
Operating System |
Dell ThinOS 2402 and 2405 |
Dell ThinOS 2408 |
09/05/2024 |
ThinOS 9.1.3129 or later to ThinOS 2408 (9.5.3102) Upgrade Image file | Driver Details |
|
OptiPlex 5400 All-in-One |
Operating System |
Dell ThinOS 2402 and 2405 |
Dell ThinOS 2408 |
09/05/2024 |
ThinOS 9.1.3129 or later to ThinOS 2408 (9.5.3102) Upgrade Image file | Driver Details |
|
OptiPlex AIO 7410 |
Operating System |
Dell ThinOS 2402 and 2405 |
Dell ThinOS 2408 |
09/05/2024 |
ThinOS 9.1.3129 or later to ThinOS 2408 (9.5.3102) Upgrade Image file | Driver Details |
|
OptiPlex AIO 7420 |
Operating System |
Dell ThinOS 2402 and 2405 |
Dell ThinOS 2408 |
09/05/2024 |
ThinOS 9.1.3129 or later to ThinOS 2408 (9.5.3102) Upgrade Image file | Driver Details |
|
Wyse 5070 Thin Client (>=32GB) |
Operating System |
Dell ThinOS 2402 and 2405 |
Dell ThinOS 2408 |
09/05/2024 |
ThinOS 9.1.3129 or later to ThinOS 2408 (9.5.3102) Upgrade Image file | Driver Details |
|
Wyse 5470 All-in-One Thin Client (>=32GB) |
Operating System |
Dell ThinOS 2402 and 2405 |
Dell ThinOS 2408 |
09/05/2024 |
ThinOS 9.1.3129 or later to ThinOS 2408 (9.5.3102) Upgrade Image file | Driver Details |
|
Wyse 5470 Mobile Thin Client (>=32GB) |
Operating System |
Dell ThinOS 2402 and 2405 |
Dell ThinOS 2408 |
09/05/2024 |
ThinOS 9.1.3129 or later to ThinOS 2408 (9.5.3102) Upgrade Image file | Driver Details |
|
Product |
Software/Firmware |
Affected Versions |
Remediated Versions |
Release Date (MM/DD/YYYY) |
Link |
|
Latitude 3420 |
Operating System |
Dell ThinOS 2402 and 2405 |
Dell ThinOS 2408 |
09/05/2024 |
ThinOS 9.1.3129 or later to ThinOS 2408 (9.5.3102) Upgrade Image file | Driver Details |
|
Latitude 3440 |
Operating System |
Dell ThinOS 2402 and 2405 |
Dell ThinOS 2408 |
09/05/2024 |
ThinOS 9.1.3129 or later to ThinOS 2408 (9.5.3102) Upgrade Image file | Driver Details |
|
Latitude 5440 |
Operating System |
Dell ThinOS 2402 and 2405 |
Dell ThinOS 2408 |
09/05/2024 |
ThinOS 9.1.3129 or later to ThinOS 2408 (9.5.3102) Upgrade Image file | Driver Details |
|
Latitude 5450 |
Operating System |
Dell ThinOS 2402 and 2405 |
Dell ThinOS 2408 |
09/05/2024 |
ThinOS 9.1.3129 or later to ThinOS 2408 (9.5.3102) Upgrade Image file | Driver Details |
|
OptiPlex 3000 Thin Client |
Operating System |
Dell ThinOS 2402 and 2405 |
Dell ThinOS 2408 |
09/05/2024 |
ThinOS 9.1.3129 or later to ThinOS 2408 (9.5.3102) Upgrade Image file | Driver Details |
|
OptiPlex 5400 All-in-One |
Operating System |
Dell ThinOS 2402 and 2405 |
Dell ThinOS 2408 |
09/05/2024 |
ThinOS 9.1.3129 or later to ThinOS 2408 (9.5.3102) Upgrade Image file | Driver Details |
|
OptiPlex AIO 7410 |
Operating System |
Dell ThinOS 2402 and 2405 |
Dell ThinOS 2408 |
09/05/2024 |
ThinOS 9.1.3129 or later to ThinOS 2408 (9.5.3102) Upgrade Image file | Driver Details |
|
OptiPlex AIO 7420 |
Operating System |
Dell ThinOS 2402 and 2405 |
Dell ThinOS 2408 |
09/05/2024 |
ThinOS 9.1.3129 or later to ThinOS 2408 (9.5.3102) Upgrade Image file | Driver Details |
|
Wyse 5070 Thin Client (>=32GB) |
Operating System |
Dell ThinOS 2402 and 2405 |
Dell ThinOS 2408 |
09/05/2024 |
ThinOS 9.1.3129 or later to ThinOS 2408 (9.5.3102) Upgrade Image file | Driver Details |
|
Wyse 5470 All-in-One Thin Client (>=32GB) |
Operating System |
Dell ThinOS 2402 and 2405 |
Dell ThinOS 2408 |
09/05/2024 |
ThinOS 9.1.3129 or later to ThinOS 2408 (9.5.3102) Upgrade Image file | Driver Details |
|
Wyse 5470 Mobile Thin Client (>=32GB) |
Operating System |
Dell ThinOS 2402 and 2405 |
Dell ThinOS 2408 |
09/05/2024 |
ThinOS 9.1.3129 or later to ThinOS 2408 (9.5.3102) Upgrade Image file | Driver Details |
Workarounds & Mitigations
None
Revision History
| Revision | Date | Description |
| 1.0 | 2024-09-09 | Initial Release |
| 2.0 | 2025-02-24 | Updated Affected Products and Remediation Table: Updated the product column to add all products affected by the vulnerability |
| 3.0 | 2025-02-25 | Updated Affected Products and Remediation Table: Updated the Wyse products in table |
Acknowledgements
CVE-2024-42427: Dell would like to thank REQON for reporting this issue