CVE-2021-21598: Low severity Dell Wyse ThinOS vulnerability
Published Aug 10, 2021
·Updated
Dell Wyse ThinOS, versions 9.0, 9.1, and 9.1 MR1, contain a Sensitive Information Disclosure Vulnerability. An authenticated attacker with physical access to the system could exploit this vulnerability to read sensitive Smartcard data in log files.
Affected Software
6 affected components
Dell Wyse ThinOS=9.0
Dell Wyse ThinOS=9.1
Dell Wyse ThinOS=9.1-mr1
Dell Wyse 3040 Thin Client
Dell Wyse 5070 Thin Client
Dell Wyse 5470 Thin Client
Remediation
Patch Available
Event History
Aug 10, 2021
CVE Published
via MITRE·07:05 PM
Data Sourced
via MITRE·07:05 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2021-21598.
2
What is the severity of CVE-2021-21598?
The severity of CVE-2021-21598 is low (3.9).
3
Which versions of Dell Wyse ThinOS are affected by CVE-2021-21598?
Dell Wyse ThinOS versions 9.0, 9.1, and 9.1 MR1 are affected by CVE-2021-21598.
4
How can an attacker exploit CVE-2021-21598?
An authenticated attacker with physical access to the system could exploit CVE-2021-21598 to read sensitive Smartcard data in log files.
5
Is Dell Wyse 3040 Thin Client vulnerable to CVE-2021-21598?
No, Dell Wyse 3040 Thin Client is not vulnerable to CVE-2021-21598.