CVE-2023-32455

Dell Wyse ThinOS versions prior to 2208 (9.3.2102) contain a sensitive information disclosure vulnerability. An unauthenticated malicious user with local access to the device could exploit this vulnerability to read sensitive information written to the log files.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:dell:wyse_thinos:*:*:*:*:*:*:*:*
OR cpe:2.3:h:dell:latitude_3420:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:latitude_3440:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:latitude_5440:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:optiplex_3000_thin_client:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:optiplex_5400:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:wyse_3040_thin_client:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:wyse_5070_thin_client:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:wyse_5470_all-in-one_thin_client:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:wyse_5470_mobile_thin_client:-:*:*:*:*:*:*:*

History

28 Jul 2023, 16:54

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
First Time Dell latitude 3420
Dell wyse 5470 All-in-one Thin Client
Dell wyse Thinos
Dell wyse 5470 Mobile Thin Client
Dell latitude 5440
Dell optiplex 3000 Thin Client
Dell wyse 3040 Thin Client
Dell latitude 3440
Dell
Dell wyse 5070 Thin Client
Dell optiplex 5400
CWE CWE-312 CWE-532
CPE cpe:2.3:h:dell:wyse_5470_mobile_thin_client:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:latitude_5440:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:wyse_thinos:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:wyse_5070_thin_client:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:optiplex_3000_thin_client:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:latitude_3420:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:wyse_5470_all-in-one_thin_client:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:latitude_3440:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:wyse_3040_thin_client:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:optiplex_5400:-:*:*:*:*:*:*:*
References (MISC) https://www.dell.com/support/kbdoc/en-us/000215864/dsa-2023-247 - (MISC) https://www.dell.com/support/kbdoc/en-us/000215864/dsa-2023-247 - Vendor Advisory

20 Jul 2023, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-07-20 13:15

Updated : 2023-12-10 15:14


NVD link : CVE-2023-32455

Mitre link : CVE-2023-32455

CVE.ORG link : CVE-2023-32455


JSON object : View

Products Affected

dell

  • wyse_thinos
  • optiplex_5400
  • wyse_5470_all-in-one_thin_client
  • optiplex_3000_thin_client
  • latitude_3440
  • wyse_5470_mobile_thin_client
  • wyse_3040_thin_client
  • latitude_5440
  • latitude_3420
  • wyse_5070_thin_client
CWE
CWE-532

Insertion of Sensitive Information into Log File

CWE-312

Cleartext Storage of Sensitive Information