PT-2019-9177 · Dell · Dell Wyse Thinlinux

Published

2019-02-13

·

Updated

2019-10-09

·

CVE-2018-15781

CVSS v3.1

8.0

High

VectorAV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Dell Wyse ThinLinux2 versions prior to 2.1.0.01
Description The issue concerns a Hard-coded Cryptographic Key. An unauthenticated remote attacker could reverse engineer the cryptographic system to discover the hard-coded private key and decrypt locally stored cipher text.
Recommendations For versions prior to 2.1.0.01, update to version 2.1.0.01 or later to resolve the issue.

Fix

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-15781

Affected Products

Dell Wyse Thinlinux