// For flags

CVE-2023-32455

 

Severity Score

5.5
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

Track
*SSVC
Descriptions

Dell Wyse ThinOS versions prior to 2208 (9.3.2102) contain a sensitive information disclosure vulnerability. An unauthenticated malicious user with local access to the device could exploit this vulnerability to read sensitive information written to the log files.

*Credits: N/A
CVSS Scores
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Attack Vector
Local
Attack Complexity
Low
Authentication
Single
Confidentiality
Complete
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:Track
Exploitation
None
Automatable
No
Tech. Impact
Partial
* Organization's Worst-case Scenario
Timeline
  • 2023-05-09 CVE Reserved
  • 2023-07-20 CVE Published
  • 2024-10-17 CVE Updated
  • 2025-03-30 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-312: Cleartext Storage of Sensitive Information
  • CWE-532: Insertion of Sensitive Information into Log File
CAPEC
References (1)
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Dell
Search vendor "Dell"
Wyse Thinos
Search vendor "Dell" for product "Wyse Thinos"
<= 9.3.2102
Search vendor "Dell" for product "Wyse Thinos" and version " <= 9.3.2102"
-
Affected
in Dell
Search vendor "Dell"
Latitude 3420
Search vendor "Dell" for product "Latitude 3420"
--
Safe
Dell
Search vendor "Dell"
Wyse Thinos
Search vendor "Dell" for product "Wyse Thinos"
<= 9.3.2102
Search vendor "Dell" for product "Wyse Thinos" and version " <= 9.3.2102"
-
Affected
in Dell
Search vendor "Dell"
Latitude 3440
Search vendor "Dell" for product "Latitude 3440"
--
Safe
Dell
Search vendor "Dell"
Wyse Thinos
Search vendor "Dell" for product "Wyse Thinos"
<= 9.3.2102
Search vendor "Dell" for product "Wyse Thinos" and version " <= 9.3.2102"
-
Affected
in Dell
Search vendor "Dell"
Latitude 5440
Search vendor "Dell" for product "Latitude 5440"
--
Safe
Dell
Search vendor "Dell"
Wyse Thinos
Search vendor "Dell" for product "Wyse Thinos"
<= 9.3.2102
Search vendor "Dell" for product "Wyse Thinos" and version " <= 9.3.2102"
-
Affected
in Dell
Search vendor "Dell"
Optiplex 3000 Thin Client
Search vendor "Dell" for product "Optiplex 3000 Thin Client"
--
Safe
Dell
Search vendor "Dell"
Wyse Thinos
Search vendor "Dell" for product "Wyse Thinos"
<= 9.3.2102
Search vendor "Dell" for product "Wyse Thinos" and version " <= 9.3.2102"
-
Affected
in Dell
Search vendor "Dell"
Optiplex 5400
Search vendor "Dell" for product "Optiplex 5400"
--
Safe
Dell
Search vendor "Dell"
Wyse Thinos
Search vendor "Dell" for product "Wyse Thinos"
<= 9.3.2102
Search vendor "Dell" for product "Wyse Thinos" and version " <= 9.3.2102"
-
Affected
in Dell
Search vendor "Dell"
Wyse 3040 Thin Client
Search vendor "Dell" for product "Wyse 3040 Thin Client"
--
Safe
Dell
Search vendor "Dell"
Wyse Thinos
Search vendor "Dell" for product "Wyse Thinos"
<= 9.3.2102
Search vendor "Dell" for product "Wyse Thinos" and version " <= 9.3.2102"
-
Affected
in Dell
Search vendor "Dell"
Wyse 5070 Thin Client
Search vendor "Dell" for product "Wyse 5070 Thin Client"
--
Safe
Dell
Search vendor "Dell"
Wyse Thinos
Search vendor "Dell" for product "Wyse Thinos"
<= 9.3.2102
Search vendor "Dell" for product "Wyse Thinos" and version " <= 9.3.2102"
-
Affected
in Dell
Search vendor "Dell"
Wyse 5470 All-in-one Thin Client
Search vendor "Dell" for product "Wyse 5470 All-in-one Thin Client"
--
Safe
Dell
Search vendor "Dell"
Wyse Thinos
Search vendor "Dell" for product "Wyse Thinos"
<= 9.3.2102
Search vendor "Dell" for product "Wyse Thinos" and version " <= 9.3.2102"
-
Affected
in Dell
Search vendor "Dell"
Wyse 5470 Mobile Thin Client
Search vendor "Dell" for product "Wyse 5470 Mobile Thin Client"
--
Safe