Skip to main content
  • Place orders quickly and easily
  • View orders and track your shipping status
  • Enjoy members-only rewards and discounts
  • Create and access a list of your products
  • Manage your Dell EMC sites, products, and product-level contacts using Company Administration.

Article Number: 000203376


DSA-2022-247: Dell Wyse ThinOS Security Update for a Regular Expression Vulnerability

Summary: Dell Wyse ThinOS remediation is available for a Regular Expression vulnerability that may be exploited by malicious users to compromise the affected system.

Article Content


Impact

Medium

Details

Proprietary Code CVEs Description CVSS
Base Score
CVSS Vector String
CVE-2022- 34402 Dell Wyse ThinOS 9.3.1129 and earlier versions contain a Regular Expression Denial of Service Vulnerability in UI. An admin privilege attacker could potentially exploit this vulnerability, leading to denial-of-service. 6.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H
Proprietary Code CVEs Description CVSS
Base Score
CVSS Vector String
CVE-2022- 34402 Dell Wyse ThinOS 9.3.1129 and earlier versions contain a Regular Expression Denial of Service Vulnerability in UI. An admin privilege attacker could potentially exploit this vulnerability, leading to denial-of-service. 6.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H
Dell Technologies recommends all customers consider both the CVSS base score and any relevant temporal and environmental scores that may impact the potential severity associated with a particular security vulnerability.

Affected Products and Remediation

Product Affected Versions Updated Versions Link to Update
Wyse 3040 Thin Client

9.1.4234, 9.1.5067,
9.1.6108, and 9.3.1129
9.3.2102 Dell Wyse ThinOS
Wyse 5070 Thin Client
Wyse 5470 Mobile Thin Client
Wyse 5470 All-in-One Thin Client
Dell OptiPlex 3000 Thin Client
Dell Latitude 3420
Product Affected Versions Updated Versions Link to Update
Wyse 3040 Thin Client

9.1.4234, 9.1.5067,
9.1.6108, and 9.3.1129
9.3.2102 Dell Wyse ThinOS
Wyse 5070 Thin Client
Wyse 5470 Mobile Thin Client
Wyse 5470 All-in-One Thin Client
Dell OptiPlex 3000 Thin Client
Dell Latitude 3420

Revision History

RevisionDateDescription
1.02022-09-14Initial Release

Related Information


Article Properties


Affected Product

Wyse ThinOS

Last Published Date

14 Sep 2022

Article Type

Dell Security Advisory