CVE-2021-21532

Description


Dell Wyse ThinOS 8.6 MR9 contains remediation for an improper management server validation vulnerability that could be potentially exploited to redirect a client to an attacker-controlled management server, thus allowing the attacker to change the device configuration or certificate file.

CvssV3 impact


BaseSeverity

MEDIUM

ConfidentialityImpact

LOW

AttackComplexity

LOW

Scope

UNCHANGED

AttackVector

ADJACENT_NETWORK

AvailabilityImpact

LOW

IntegrityImpact

LOW

PrivilegesRequired

NONE

BaseScore

6.3

VectorString

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Version

3.1

UserInteraction

NONE

CvssV2 impact


AccessComplexity

LOW

ConfidentialityImpact

PARTIAL

AvailabilityImpact

PARTIAL

IntegrityImpact

PARTIAL

BaseScore

5.8

VectorString

AV:A/AC:L/Au:N/C:P/I:P/A:P

Version

2.0

AccessVector

ADJACENT_NETWORK

Authentication

NONE