{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-06-26T14:54:37.349","vulnerabilities":[{"cve":{"id":"CVE-2024-42427","sourceIdentifier":"security_alert@emc.com","published":"2024-09-10T08:15:02.760","lastModified":"2026-06-17T07:49:26.647","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Dell ThinOS versions 2402 and 2405, contains an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Elevation of privileges."},{"lang":"es","value":"Las versiones 2402 y 2405 de Dell ThinOS contienen una vulnerabilidad de neutralización inadecuada de elementos especiales utilizados en un comando ('inyección de comando'). Un atacante no autenticado con acceso físico podría aprovechar esta vulnerabilidad, lo que provocaría una elevación de privilegios."}],"affected":[{"source":"security_alert@emc.com","affectedData":[{"vendor":"Dell","product":"Wyse Proprietary OS (Modern ThinOS)","defaultStatus":"unaffected","versions":[{"version":"Dell ThinOS 2402","status":"affected"},{"version":"Dell ThinOS 2405","status":"affected"}]}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","affectedData":[{"vendor":"dell","product":"wyse_proprietary_os","defaultStatus":"unknown","cpes":["cpe:2.3:a:dell:wyse_proprietary_os:*:*:*:*:*:*:*:*"],"versions":[{"version":"2402","status":"affected"},{"version":"2405","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security_alert@emc.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","baseScore":7.6,"baseSeverity":"HIGH","attackVector":"PHYSICAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":0.9,"impactScore":6.0},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","baseScore":7.6,"baseSeverity":"HIGH","attackVector":"PHYSICAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":0.9,"impactScore":6.0}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-09-10T15:12:09.321890Z","id":"CVE-2024-42427","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security_alert@emc.com","type":"Secondary","description":[{"lang":"en","value":"CWE-77"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-77"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:dell:wyse_thinos:9.5.1079:*:*:*:*:*:*:*","matchCriteriaId":"4912456C-F4B9-4B5E-82DC-BA3BB28456A5"},{"vulnerable":true,"criteria":"cpe:2.3:o:dell:wyse_thinos:9.5.2109:*:*:*:*:*:*:*","matchCriteriaId":"62BCEB7B-BC2B-4DB3-8D70-16E67D63EE2E"}]}]}],"references":[{"url":"https://www.dell.com/support/kbdoc/en-us/000228350/dsa-2024-386","source":"security_alert@emc.com","tags":["Vendor Advisory"]}]}}]}