CVE-2024-42427: Command Injection
Dell ThinOS versions 2402 and 2405, contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Elevation of privileges.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-42427?
CVE-2024-42427 is considered a high severity vulnerability due to its potential for privilege escalation.
How do I fix CVE-2024-42427?
To fix CVE-2024-42427, update Dell ThinOS to the latest version that addresses this vulnerability.
Who is affected by CVE-2024-42427?
CVE-2024-42427 affects users of Dell ThinOS versions 2402 and 2405, specifically versions 9.5.1079 and 9.5.2109.
What type of vulnerability is CVE-2024-42427?
CVE-2024-42427 is a command injection vulnerability allowing unauthenticated attackers with physical access to exploit the system.
Can CVE-2024-42427 be exploited remotely?
No, CVE-2024-42427 requires physical access to the affected device for exploitation.