CVE-2025-43882 Details
Description
Dell ThinOS 10, versions prior to 2508_10.0127, contains an Unverified Ownership vulnerability. A local low-privileged attacker could potentially exploit this vulnerability leading to Unauthorized Access.
A vulnerability has been identified in Dell ThinOS 10, specifically in versions prior to 2508_10.0127. This vulnerability allows a local low-privileged attacker to potentially exploit the system, leading to unauthorized access. The issue arises from unverified ownership, which could be manipulated to gain access rights or privileges that should not be available.
Users can upgrade to ThinOS 10_2508_0127 or later to address this vulnerability. The update can be downloaded as part of the ThinOS 10 2508 Offline USB Installer Package, available through the Dell Support website.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Aug 28, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.dell.com/support/kbdoc/en-us/000359619/dsa-2025-331 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
| CWE-283 | Unverified Ownership | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| dell thinos | < 2508 |
CPE
Remediation
| |
| dell latitude 3330 | All versions |
CPE
Remediation
| |
| dell latitude 3420 | All versions |
CPE
Remediation
| |
| dell latitude 3440 | All versions |
CPE
Remediation
| |
| dell latitude 3450 | All versions |
CPE
Remediation
| |
| dell latitude 5440 | All versions |
CPE
Remediation
| |
| dell latitude 5450 | All versions |
CPE
Remediation
| |
| dell latitude 5520 | All versions |
CPE
Remediation
| |
| dell latitude 5530 | All versions |
CPE
Remediation
| |
| dell latitude 5540 | All versions |
CPE
Remediation
| |
| dell latitude 5550 | All versions |
CPE
Remediation
| |
| dell optiplex 3000 tc | All versions |
CPE
Remediation
| |
| dell optiplex 5400 all-in-one | All versions |
CPE
Remediation
| |
| dell optiplex 7020 | All versions |
CPE
Remediation
| |
| dell optiplex all-in-one 7410 | All versions |
CPE
Remediation
| |
| dell optiplex all-in-one 7420 | All versions |
CPE
Remediation
| |
| dell optiplex micro plus 7010 | All versions |
CPE
Remediation
| |
| dell precision 3260 compact | All versions |
CPE
Remediation
| |
| dell precision 3280 | All versions |
CPE
Remediation
| |
| dell pro 14 pc14250 | All versions |
CPE
Remediation
| |
| dell pro 16 pc16250 | All versions |
CPE
Remediation
| |
| dell pro 16 plus pb16250 | All versions |
CPE
Remediation
| |
| dell pro 24 all-in-one | All versions |
CPE
Remediation
| |
| dell pro max 14 | All versions |
CPE
Remediation
| |
| dell pro max 16 plus | All versions |
CPE
Remediation
| |
| dell pro rugged 13 ra13250 | All versions |
CPE
Remediation
| |
| dell pro rugged 14 rb14250 | All versions |
CPE
Remediation
| |
| dell pro slim low sff | All versions |
CPE
Remediation
| |
| dell pro tower qct1250 | All versions |
CPE
Remediation
| |
| dell wyse 5070 extended thin client | All versions |
CPE
Remediation
| |
| dell wyse 5070 thin client | All versions |
CPE
Remediation
| |
| dell wyse 5470 all-in-one thin client | All versions |
CPE
Remediation
| |
| dell wyse 5470 mtc | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 15, 2026 | Initial Analysis | [email protected] |
| Aug 27, 2025 | New CVE Received | [email protected] |