CVE-2025-43730
HIGH EPSS 9.5%
Published Aug 27, 202510mo ago · Modified Jun 17, 20261w ago
7.8 CVSS 3.1
Published Aug 27, 2025 10mo ago
Last Modified Jun 17, 2026 1w ago
Description
Dell ThinOS 10, versions prior to 2508_10.0127, contains an Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability. A local unauthenticated user could potentially exploit this vulnerability leading to Elevation of Privileges and Information disclosure.
CVSS Details
Base Score
Exploitability
Impact
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Attack Vector Local
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality High
Integrity High
Availability High
Threat Intelligence
EPSS Exploit Probability
9.5% percentile
Exploit & Patch Status
No Known Exploit
No Patch Available
Weaknesses 1
CWE-88
Affected Products 33
| Vendor | Product | Version | Range |
|---|---|---|---|
| dell | thinos | * | <2508 |
| dell | latitude_3330 | * | any |
| dell | latitude_3420 | * | any |
| dell | latitude_3440 | * | any |
| dell | latitude_3450 | * | any |
| dell | latitude_5440 | * | any |
| dell | latitude_5450 | * | any |
| dell | latitude_5520 | * | any |
| dell | latitude_5530 | * | any |
| dell | latitude_5540 | * | any |
| dell | latitude_5550 | * | any |
| dell | optiplex_3000_tc | * | any |
| dell | optiplex_5400_all-in-one | * | any |
| dell | optiplex_7020 | * | any |
| dell | optiplex_all-in-one_7410 | * | any |
| dell | optiplex_all-in-one_7420 | * | any |
| dell | optiplex_micro_plus_7010 | * | any |
| dell | precision_3260_compact | * | any |
| dell | precision_3280 | * | any |
| dell | pro_14_pc14250 | * | any |
| dell | pro_16_pc16250 | * | any |
| dell | pro_16_plus_pb16250 | * | any |
| dell | pro_24_all-in-one | * | any |
| dell | pro_max_14 | * | any |
| dell | pro_max_16_plus | * | any |
| dell | pro_rugged_13_ra13250 | * | any |
| dell | pro_rugged_14_rb14250 | * | any |
| dell | pro_slim_low_sff | * | any |
| dell | pro_tower_qct1250 | * | any |
| dell | wyse_5070_extended_thin_client | * | any |
| dell | wyse_5070_thin_client | * | any |
| dell | wyse_5470_all-in-one_thin_client | * | any |
| dell | wyse_5470_mtc | * | any |
References 1
- dell.com https://www.dell.com/support/kbdoc/en-us/000359619/dsa-2025-331
Remediation
No remediation data recorded yet
Check vendor advisories and the NVD entry for patch availability.