Dell Wyse ThinOS versions prior to 2303 (9.4.1141) contain a sensitive information disclosure vulnerability. An unauthenticated malicious user with local access to the device could exploit this vulnerability to read sensitive information written to the log files.
The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.
The product writes sensitive information to a log file.
Link | Tags |
---|---|
https://www.dell.com/support/kbdoc/en-us/000215864/dsa-2023-247 | vendor advisory |