HomeSecurityCritical bugs in Dell Wyse ThinOS

Critical errors in Dell Wyse ThinOS

Nearly a dozen Dell Wyse thin client models are vulnerable to critical issues that could be exploited by a hacker to execute malicious code and gain access to arbitrary files.

Dell Wyse

Thin clients are small computers used for remote desktop connections to a more powerful system. They are popular in organizations that do not need computers with high processing power, storage, and memory on the network.

It is estimated that more than 6,000 organizations, most of them from the healthcare sector, have used Dell Wyse thin clients in their networks.

The vulnerabilities (reported as CVE-2020-29492 and CVE-2020-29491) are located in components of ThinOS, the operating system for Dell Wyse thin clients.

ThinOS can be supported remotely. Dell's suggestion for this process is to set up an FTP server for devices to receive updates (firmware, packages, configurations).

Security researchers at CyberMDX, a company focused on cybersecurity in the healthcare sector, found that FTP access is possible without credentials, using an “anonymous” user.

They also discovered that only the firmware and packages are signed, leaving the INI configuration files as a potential way for use them to do some damage.

Elad Luz, head of research at CyberMDX, says that there is a specific INI file on the FTP server that must be writable for connecting clients.

Protecting the FTP connection with credentials wouldn't be enough, Luz says, because the username and password would be shared across all thin clients.

The researcher explains that when a Dell Wyse device connects to the FTP server, it looks for the INI file that holds its configuration and its name from the username used on the terminal.

With this file writable, an attacker can install a malicious version to control the configuration that a particular user on the network.

According to CyberMDX, these vulnerabilities affect the following Dell Wyse models running ThinOS 8.6 and below:

Critical errors in Dell Wyse ThinOS

Dell has released ThinOS 9.x to address these issues. However, some of the affected models can no longer be upgraded:

  • Wyse 3020
  • Wyse 3030 LT
  • Wyse 5010
  • Wyse 5040 AIO
  • Wyse 5060
  • Wyse 7010

CyberMDX recommends that organizations with the above models deployed on their networks disable the use of FTP for the update and rely on an alternative method for the task.

In its security advisory, Dell recommends protecting the environment by using a secure protocol (HTTPS) and ensuring that file servers have read-only access.

Additionally, affected customers can use Wyse Management Suite for device imaging and configuration, which enforces the use of HTTPS and stores configuration files in a secure server database.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS