CVE-2023-32447

Dell Wyse ThinOS versions prior to 2306 (9.4.2103) contain a sensitive information disclosure vulnerability. A malicious user with local access to the device could exploit this vulnerability to read sensitive information written to the log files.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:dell:wyse_thinos:*:*:*:*:*:*:*:*
OR cpe:2.3:h:dell:latitude_3420:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:latitude_3440:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:latitude_5440:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:optiplex_3000_thin_client:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:optiplex_5400:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:wyse_3040_thin_client:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:wyse_5070_thin_client:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:wyse_5470_all-in-one_thin_client:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:wyse_5470_mobile_thin_client:-:*:*:*:*:*:*:*

History

21 Nov 2024, 08:03

Type Values Removed Values Added
References () https://www.dell.com/support/kbdoc/en-us/000215864/dsa-2023-247 - Vendor Advisory () https://www.dell.com/support/kbdoc/en-us/000215864/dsa-2023-247 - Vendor Advisory

28 Jul 2023, 16:47

Type Values Removed Values Added
CPE cpe:2.3:h:dell:wyse_5070_thin_client:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:latitude_3420:-:*:*:*:*:*:*:*
cpe:2.3:o:dell:wyse_thinos:*:*:*:*:*:*:*:*
cpe:2.3:h:dell:wyse_5470_mobile_thin_client:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:latitude_5440:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:wyse_3040_thin_client:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:wyse_5470_all-in-one_thin_client:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:optiplex_3000_thin_client:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:optiplex_5400:-:*:*:*:*:*:*:*
cpe:2.3:h:dell:latitude_3440:-:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
CWE CWE-312 CWE-532
References (MISC) https://www.dell.com/support/kbdoc/en-us/000215864/dsa-2023-247 - (MISC) https://www.dell.com/support/kbdoc/en-us/000215864/dsa-2023-247 - Vendor Advisory
First Time Dell latitude 5440
Dell wyse 5470 All-in-one Thin Client
Dell optiplex 5400
Dell wyse 5470 Mobile Thin Client
Dell latitude 3420
Dell latitude 3440
Dell wyse 5070 Thin Client
Dell wyse Thinos
Dell optiplex 3000 Thin Client
Dell
Dell wyse 3040 Thin Client

20 Jul 2023, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-07-20 13:15

Updated : 2024-11-21 08:03


NVD link : CVE-2023-32447

Mitre link : CVE-2023-32447

CVE.ORG link : CVE-2023-32447


JSON object : View

Products Affected

dell

  • wyse_5470_mobile_thin_client
  • latitude_3420
  • wyse_thinos
  • latitude_5440
  • optiplex_3000_thin_client
  • wyse_5470_all-in-one_thin_client
  • wyse_3040_thin_client
  • optiplex_5400
  • latitude_3440
  • wyse_5070_thin_client
CWE
CWE-312

Cleartext Storage of Sensitive Information

CWE-532

Insertion of Sensitive Information into Log File