CVE-2025-43882
HIGHDescription
Dell ThinOS 10, versions prior to 2508_10.0127, contains an Unverified Ownership vulnerability. A local low-privileged attacker could potentially exploit this vulnerability leading to Unauthorized Access.
Is your site exposed to CVE-2025-43882?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| dell | thinos |
| dell | latitude_3330 |
| dell | latitude_3420 |
| dell | latitude_3440 |
| dell | latitude_3450 |
| dell | latitude_5440 |
| dell | latitude_5450 |
| dell | latitude_5520 |
| dell | latitude_5530 |
| dell | latitude_5540 |
| dell | latitude_5550 |
| dell | optiplex_3000_tc |
| dell | optiplex_5400_all-in-one |
| dell | optiplex_7020 |
| dell | optiplex_all-in-one_7410 |
| dell | optiplex_all-in-one_7420 |
| dell | optiplex_micro_plus_7010 |
| dell | precision_3260_compact |
| dell | precision_3280 |
| dell | pro_14_pc14250 |
| dell | pro_16_pc16250 |
| dell | pro_16_plus_pb16250 |
| dell | pro_24_all-in-one |
| dell | pro_max_14 |
| dell | pro_max_16_plus |
| dell | pro_rugged_13_ra13250 |
| dell | pro_rugged_14_rb14250 |
| dell | pro_slim_low_sff |
| dell | pro_tower_qct1250 |
| dell | wyse_5070_extended_thin_client |
| dell | wyse_5070_thin_client |
| dell | wyse_5470_all-in-one_thin_client |
| dell | wyse_5470_mtc |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2025-43882? +
How severe is CVE-2025-43882? +
What products are affected by CVE-2025-43882? +
How do I check if I'm vulnerable to CVE-2025-43882? +
Related Vulnerabilities
OpenVPN plug-ins on Windows with OpenVPN 2.6.9 and earlier could be loaded from any directory, which allows an attacker to …
Unverified ownership of a storage access point in the volume deletion component of the Amazon EFS CSI Driver before v3.4.1 …
TYPO3 is an open source, PHP based web content management system. Starting in version 10.0.0 and prior to versions 10.4.50 …
On the Trusted Firmware-M (TF-M) 2 through 2.3.0 platform before 00d1b3e, mailbox initialization on PSOC64 and RP2350 accepts a non-secure, …
Chatwoot is a customer engagement suite. From 2.14.0 to before 4.13.0, a Pre-Account Takeover (Pre-ATO) vulnerability existed in Chatwoot's authentication …
gitoxide is an implementation of git written in Rust. Prior to 0.13.3, the gix-sec crate on Windows incorrectly treats repositories …