Executive brief
Dell ThinOS 10, an operating system used in thin client devices for secure cloud and virtual desktop access, contains a security flaw in its protection mechanisms. An attacker with physical access to the device could bypass security controls to access encrypted data stored on the system. This could lead to the exposure of sensitive information if a device is lost, stolen, or accessed by unauthorized personnel in person.
Technical details
Dell ThinOS 10 is vulnerable to a Protection Mechanism Failure (CWE-693) in versions prior to 2605_10.2100. The vulnerability exists within the proprietary code of the operating system. An attacker with physical access to the hardware can exploit this failure to bypass encryption protections and gain unauthorized access to data. The attack requires no prior privileges or user interaction but is limited by the requirement for physical proximity to the device. Dell has released version 2605_10.2100 to remediate this issue.
Affected products
- Dell ThinOS 10 prior to 2605_10.2100
Timeline
- 2026-07-03: patched: Remediated version 2605_10.2100 released.
- 2026-07-15: advisory: Dell Security Advisory DSA-2026-300 published.
- 2026-07-15: disclosed