The giant Dell Wyse is affected by two Critical Vulnerabilities CVE-2020-29491 and CVE-2020-29492 which targets thin client devices.
The CyberMDX Research team has discovered these vulnerabilities on Dell Wyse thin clients, wherein when the vulnerability is exploited, the attackers can run malicious codes remotely and access arbitrary files on the affected devices.
A thin client is a small form-factor computer optimized for performing a remote desktop connection to a distant (and usually) more resourceful hardware. The software used by the thin client is minimal and directed towards making a seamless remote connection experience.
These CVE-2020-29491 and CVE-2020-29492 are the default configuration vulnerabilities that can access a writable file and can manipulate the configuration of a specific thin client and potentially gain access to sensitive information on it compromising the thin clients completely. The impact is marked as ‘Critical’ by DELL.
All the Dell Wyse Thin Clients running on ThinOS versions 8.6 are affected
Product | Affected Version(s) | Updated Version(s) |
Dell Wyse 3040 Thin Client (ENG) | Versions prior to 8.6 MR8 where the Client is receiving configurations from a remote file server over an insecure protocol | 8.6 MR8 |
Dell Wyse 3040 Thin Client (JPN) | Versions prior to 8.6 MR8 where the Client is receiving configurations from a remote file server over an insecure protocol | 8.6 MR8 |
Dell Wyse 3040 Thin Client with PCoIP (ENG) | Versions prior to 8.6 MR8 where the Client is receiving configurations from a remote file server over an insecure protocol | 8.6 MR8 |
Dell Wyse 3040 Thin Client with PCoIP (JPN) | Versions prior to 8.6 MR8 where the Client is receiving configurations from a remote file server over an insecure protocol | 8.6 MR8 |
Dell Wyse 5010 Thin Client (ENG) | Versions prior to 8.6 MR8 where the Client is receiving configurations from a remote file server over an insecure protocol | 8.6 MR8 |
Dell Wyse 5010 Thin Client (JPN) | Versions prior to 8.6 MR8 where the Client is receiving configurations from a remote file server over an insecure protocol | 8.6 MR8 |
Dell Wyse 5010 Thin Client with PCoIP (ENG) | Versions prior to 8.6 MR8 where the Client is receiving configurations from a remote file server over an insecure protocol | 8.6 MR8 |
Dell Wyse 5010 Thin Client with PCoIP (JPN) | Versions prior to 8.6 MR8 where the Client is receiving configurations from a remote file server over an insecure protocol | 8.6 MR8 |
Dell Wyse 5040 Thin Client (ENG) | Versions prior to 8.6 MR8 where the Client is receiving configurations from a remote file server over an insecure protocol | 8.6 MR8 |
Dell Wyse 5040 Thin Client (JPN) | Versions prior to 8.6 MR8 where the Client is receiving configurations from a remote file server over an insecure protocol | 8.6 MR8 |
Dell Wyse 5040 Thin Client with PCoIP (ENG) | Versions prior to 8.6 MR8 where the Client is receiving configurations from a remote file server over an insecure protocol | 8.6 MR8 |
Dell Wyse 5040 Thin Client with PCoIP (JPN) | Versions prior to 8.6 MR8 where the Client is receiving configurations from a remote file server over an insecure protocol | 8.6 MR8 |
Dell Wyse 5060 Thin Client (ENG) | Versions prior to 8.6 MR8 where the Client is receiving configurations from a remote file server over an insecure protocol | 8.6 MR8 |
Dell Wyse 5060 Thin Client (JPN) | Versions prior to 8.6 MR8 where the Client is receiving configurations from a remote file server over an insecure protocol | 8.6 MR8 |
Dell Wyse 5060 Thin Client with PCoIP (ENG) | Versions prior to 8.6 MR8 where the Client is receiving configurations from a remote file server over an insecure protocol | 8.6 MR8 |
Dell Wyse 5060 Thin Client with PCoIP (JPN) | Versions prior to 8.6 MR8 where the Client is receiving configurations from a remote file server over an insecure protocol | 8.6 MR8 |
Dell Wyse 5070 Thin Client (ENG) | Versions prior to 8.6 MR8 where the Client is receiving configurations from a remote file server over an insecure protocol | 8.6 MR8 |
Dell Wyse 5070 Thin Client (JPN) | Versions prior to 8.6 MR8 where the Client is receiving configurations from a remote file server over an insecure protocol | 8.6 MR8 |
Dell Wyse 5070 Thin Client with PCoIP (ENG) | Versions prior to 8.6 MR8 where the Client is receiving configurations from a remote file server over an insecure protocol | 8.6 MR8 |
Dell Wyse 5070 Thin Client with PCoIP (JPN) | Versions prior to 8.6 MR8 where the Client is receiving configurations from a remote file server over an insecure protocol | 8.6 MR8 |
Dell Wyse 5470 AIO Thin Client (ENG) | Versions prior to 8.6 MR8 where the Client is receiving configurations from a remote file server over an insecure protocol | 8.6 MR8 |
Dell Wyse 5470 AIO Thin Client (JPN) | Versions prior to 8.6 MR8 where the Client is receiving configurations from a remote file server over an insecure protocol | 8.6 MR8 |
Dell Wyse 5470 AIO Thin Client with PCoIP (ENG) | Versions prior to 8.6 MR8 where the Client is receiving configurations from a remote file server over an insecure protocol | 8.6 MR8 |
Dell Wyse 5470 AIO Thin Client with PCoIP (JPN) | Versions prior to 8.6 MR8 where the Client is receiving configurations from a remote file server over an insecure protocol | 8.6 MR8 |
Dell Wyse 5470 Thin Client (ENG) | Versions prior to 8.6 MR8 where the Client is receiving configurations from a remote file server over an insecure protocol | 8.6 MR8 |
Dell Wyse 5470 Thin Client (JPN) | Versions prior to 8.6 MR8 where the Client is receiving configurations from a remote file server over an insecure protocol | 8.6 MR8 |
Dell Wyse 5470 Thin Client with PCoIP (ENG) | Versions prior to 8.6 MR8 where the Client is receiving configurations from a remote file server over an insecure protocol | 8.6 MR8 |
Dell Wyse 5470 Thin Client with PCoIP (JPN) | Versions prior to 8.6 MR8 where the Client is receiving configurations from a remote file server over an insecure protocol | 8.6 MR8 |
Dell Wyse 7010 Thin Client (ENG) | Versions prior to 8.6 MR8 where the Client is receiving configurations from a remote file server over an insecure protocol | 8.6 MR8 |
Dell Wyse 7010 thin client (JPN) | Versions prior to 8.6 MR8 where the Client is receiving configurations from a remote file server over an insecure protocol | 8.6 MR8 |
Dell Wyse thin client is widely used that around 6000 companies and organizations are making use of it in America alone. So it is likely to see that majority of Customers are under pressure to be cautious with the vulnerability.
Dell recommends customers to implement one of the following:
You can follow us on Linkedin, Twitter, Facebook for daily Cybersecurity, and hacking news updates.
Also Read
A critical security flaw has been uncovered in certain TP-Link routers, potentially allowing malicious actors…
SilkSpecter, a Chinese financially motivated threat actor, launched a sophisticated phishing campaign targeting e-commerce shoppers…
The research revealed how threat actors exploit SEO poisoning to redirect unsuspecting users to malicious…
Black Basta, a prominent ransomware group, has rapidly gained notoriety since its emergence in 2022…
CVE-2024-52301 is a critical vulnerability identified in Laravel, a widely used PHP framework for building…
A critical vulnerability has been discovered in the popular "Really Simple Security" WordPress plugin, formerly…