DSA-2023-247: Dell ThinOS Security Update for Multiple Vulnerabilities

Resumo: Dell ThinOS remediation is available for multiple vulnerabilities that could be exploited by malicious users to compromise the affected system

Este artigo aplica-se a Este artigo não se aplica a Este artigo não está vinculado a nenhum produto específico. Nem todas as versões do produto estão identificadas neste artigo.

Impacto

Medium

Dados

Proprietary Code CVE(s) Description CVSS Base Score CVSS Vector String
CVE-2023-32455 Dell Wyse ThinOS versions prior to 2208 (9.3.2102) contain a sensitive information disclosure vulnerability. An unauthenticated malicious user with local access to the device could exploit this vulnerability to read sensitive information written to the log files. 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVE-2023-32446 Dell Wyse ThinOS versions prior to 2303 (9.4.1141) contain a sensitive information disclosure vulnerability. An unauthenticated malicious user with local access to the device could exploit this vulnerability to read sensitive information written to the log files. 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVE-2023-32447 Dell Wyse ThinOS versions prior to 2306 (9.4.2103) contain a sensitive information disclosure vulnerability. A malicious user with local access to the device could exploit this vulnerability to read sensitive information written to the log files. 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Proprietary Code CVE(s) Description CVSS Base Score CVSS Vector String
CVE-2023-32455 Dell Wyse ThinOS versions prior to 2208 (9.3.2102) contain a sensitive information disclosure vulnerability. An unauthenticated malicious user with local access to the device could exploit this vulnerability to read sensitive information written to the log files. 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVE-2023-32446 Dell Wyse ThinOS versions prior to 2303 (9.4.1141) contain a sensitive information disclosure vulnerability. An unauthenticated malicious user with local access to the device could exploit this vulnerability to read sensitive information written to the log files. 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVE-2023-32447 Dell Wyse ThinOS versions prior to 2306 (9.4.2103) contain a sensitive information disclosure vulnerability. A malicious user with local access to the device could exploit this vulnerability to read sensitive information written to the log files. 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
A Dell Technologies recomenda que todos os clientes levem em consideração a pontuação base CVSS e as pontuações temporais e ambientais pertinentes que possam afetar a gravidade potencial associada a uma vulnerabilidade de segurança específica.

Produtos afetados e soluções

Product Affected Version(s) Updated Version(s) Link to Update
Wyse 3040 Thin Client
2208 (9.3.2102) and below 
(CVE-2023-32455)

2303 (9.4.1141)
(CVE-2023-32446)

2303(9.4.1141) and below
(CVE-2023-32447)

2306 (9.4.2103)

Dell Wyse ThinOS
Wyse 5070 Thin Client
Wyse 5470 Mobile Thin Client
Wyse 5470 All-in-One Thin Client
Dell OptiPlex 3000 Thin Client
Dell Latitude 3420
Dell OptiPlex 5400 All-in-One
Dell Latitude 3440
Dell Latitude 5440
Dell OptiPlex All-in-One
Product Affected Version(s) Updated Version(s) Link to Update
Wyse 3040 Thin Client
2208 (9.3.2102) and below 
(CVE-2023-32455)

2303 (9.4.1141)
(CVE-2023-32446)

2303(9.4.1141) and below
(CVE-2023-32447)

2306 (9.4.2103)

Dell Wyse ThinOS
Wyse 5070 Thin Client
Wyse 5470 Mobile Thin Client
Wyse 5470 All-in-One Thin Client
Dell OptiPlex 3000 Thin Client
Dell Latitude 3420
Dell OptiPlex 5400 All-in-One
Dell Latitude 3440
Dell Latitude 5440
Dell OptiPlex All-in-One

Histórico de revisão

RevisionDateDescription
1.02023-07-18Initial Release

Informações relacionadas

Produtos afetados

OptiPlex All-In-One, Latitude 3440, Latitude 5440, OptiPlex 3000 Thin Client, OptiPlex 5400 All-In-One, Wyse 3040 Thin Client, Wyse 5070 Thin Client, Wyse 5470 All-In-One, Wyse 5470
Propriedades do artigo
Número do artigo: 000215864
Tipo de artigo: Dell Security Advisory
Último modificado: 18 jul. 2023
Encontre as respostas de outros usuários da Dell para suas perguntas.
Serviços de suporte
Verifique se o dispositivo está coberto pelos serviços de suporte.