PT-2012-1270 · Dell · Wyse Device Manager

Kevin Finisterre

·

Published

2012-06-19

·

Updated

2012-06-26

·

CVE-2009-0695

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Wyse Device Manager (WDM) versions 4.7.x
Description The issue allows remote attackers to obtain management access without requiring authentication for commands. This can be achieved by sending a crafted query, such as a V52 query, which can trigger actions like powering off the device.
Recommendations For Wyse Device Manager (WDM) versions 4.7.x, consider restricting access to the hagent.exe component to minimize the risk of exploitation until a patch is available. As a temporary workaround, limit the ability to send crafted queries to the affected system.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-0695

Affected Products

Wyse Device Manager