CVE-2021-21532

MEDIUM

Dell Wyse ThinOS < 8.6 - Improper Management Server Validation

Title source: llm
STIX 2.1

Description

Dell Wyse ThinOS 8.6 MR9 contains remediation for an improper management server validation vulnerability that could be potentially exploited to redirect a client to an attacker-controlled management server, thus allowing the attacker to change the device configuration or certificate file.

Scores

CVSS v3 5.0
EPSS 0.0005
EPSS Percentile 16.2%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L

Details

CWE
CWE-16 CWE-20
Status published
Products (2)
dell/wyse_thinos 8.6
dell/wyse_thinos < 8.6
Published Apr 02, 2021
Tracked Since Feb 18, 2026