PT-2012-1270 · Dell · Wyse Device Manager

Kevin Finisterre

·

Publicado

2012-06-19

·

Atualizado

2012-06-26

·

CVE-2009-0695

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Wyse Device Manager (WDM) versions 4.7.x
Description The issue allows remote attackers to obtain management access without requiring authentication for commands. This can be achieved by sending a crafted query, such as a V52 query, which can trigger actions like powering off the device.
Recommendations For Wyse Device Manager (WDM) versions 4.7.x, consider restricting access to the hagent.exe component to minimize the risk of exploitation until a patch is available. As a temporary workaround, limit the ability to send crafted queries to the affected system.

Exploit

Correção

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2009-0695

Produtos afetados

Wyse Device Manager