• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
Vulnerabilities Found In Dell Wyse Thin Clients Could Enable Access

Vulnerabilities found in Dell Wyse thin clients could enable access to arbitrary files

You are here: Home / General Cyber Security News / Vulnerabilities found in Dell Wyse thin clients could enable access to arbitrary files
December 22, 2020

Scientists described Monday that they uncovered two vulnerabilities in Dell Wyse slender shopper gadgets. (Jjpwiki/CC BY-SA 4.)

Scientists documented Monday that they uncovered two vulnerabilities in Dell Wyse thin consumer equipment that have been offered scores of 10 underneath the Frequent Vulnerability Scoring Technique – the greatest severity rating.

Overall health treatment cybersecurity service provider CyberMDX, which posted the findings in a blog site, said attackers could most likely run malicious code and access arbitrary information on the influenced machines.

✔ Approved From Our Partners
AOMEI Backupper Lifetime

Protect and backup your data using AOMEI Backupper. AOMEI Backupper takes secure and encrypted backups from your Windows, hard drives or partitions. With AOMEI Backupper you will never be worried about loosing your data anymore.

Get AOMEI Backupper with 72% discount from an authorized distrinutor of AOMEI: SerialCart® (Limited Offer).

➤ Activate Your Coupon Code


The slender consumers run more than Dell Wyse ThinOS 8.6 and prior functioning programs. Wyse has been building skinny shoppers due to the fact the 1990s and was acquired by Dell in 2012. In the U.S. by itself, some 6,000 firms and corporations run Dell Wyse thin clientele inside their networks, a lot of of which are health and fitness treatment suppliers.

Dell has remediated the vulnerabilities and posted information in a Dell Security Advisory (DSA-2020-281).

In accordance to CyberMDX, both equally vulnerabilities had been supplied CVSS scores of 10. The first vulnerability, CVE-2020-29491, allows people obtain the configuration server and read through configurations belonging to other clients. The configuration may well contain delicate details, like potential passwords and account facts that could later be used to compromise the unit. The second vulnerability, CVE-2020-29492, lets users access the server and immediately alter configurations belonging to other thin customers.  

The skinny consumer gadgets are small variety-factor personal computers optimized for performing a remote desktop link to distant more resourceful components, most notably by means of  a neighborhood FTP server the place equipment pull new firmware, deals, and configurations.

“One of the principal issues is that security typically receives disregarded through the design stage of these equipment,” said Elad Luz, head of investigate at CyberMDX. “The default set up of the server for the thin client products FTP server is configured to have no qualifications and this allows any individual on the network to obtain the FTP server and modify the INI file keeping configuration settings for the thin customer products. But even if credentials are enforced they would still have to be shared across the overall skinny customer fleet, which would enable any slim consumer obtain and/or modify the configuration of all other slender shoppers within the network.”

Craig Young, principal security researcher for Tripwire’s vulnerability and exposure investigate group, stated the product of devices pulling configurations from a shared anonymous FTP server with globe-writable configuration information was something that “wouldn’t appear out of place” 20-30 yrs ago. He observed that the strategy that any variety of overall health care vendors even now work their networks like this ought to elevate much more than a handful of eyebrows.

“Problems with authentication and authorization plague a large amount of embedded devices and it appears that vendors are poorly in need of reliable suggestions relating to what is effective and what doesn’t,” Youthful said.


Some sections of this write-up are sourced from:
www.scmagazine.com

Previous Post: «The Solarwinds Hack, And The Danger Of Arrogance The SolarWinds hack, and the danger of arrogance
Next Post: New Critical Flaws in Treck TCP/IP Stack Affect Millions of IoT Devices New Critical Flaws In Treck Tcp/ip Stack Affect Millions Of»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Zero-Click Agentic Browser Attack Can Delete Entire Google Drive Using Crafted Emails
  • Critical XXE Bug CVE-2025-66516 (CVSS 10.0) Hits Apache Tika, Requires Urgent Patch
  • Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability
  • Intellexa Leaks Reveal Zero-Days and Ads-Based Vector for Predator Spyware Delivery
  • “Getting to Yes”: An Anti-Sales Guide for MSPs
  • CISA Reports PRC Hackers Using BRICKSTORM for Long-Term Access in U.S. Systems
  • JPCERT Confirms Active Command Injection Attacks on Array AG Gateways
  • Silver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in China
  • ThreatsDay Bulletin: Wi-Fi Hack, npm Worm, DeFi Theft, Phishing Blasts— and 15 More Stories
  • 5 Threats That Reshaped Web Security This Year [2025]

Copyright © TheCyberSecurity.News, All Rights Reserved.