Overview
Wyse Simple Imager (WSI) includes older versions version of TFTPD32 that contains publicly known vulnerabilities. An attacker could exploit these vulnerabilities to potentially execute arbitrary code on the system running WSI and TFTPD32.
Description
Wyse Simple Imager (WSI) is a component of Wyse Device Manager (WDM, formerly known as Wyse Rapport). WSI includes TFTPD32 as the TFTP service to load firmware images on client devices. The versions of TFTPD32 contains several known vulnerabilities. The following list of TFTPD32 vulnerabilities is based on public information:
|
Impact
An attacker with network access to TFTPD32 could execute arbitrary code or cause a denial of service on a vulnerable system. |
Solution
Use Wyse WDM and USB Imaging Tool
|
Restrict Access to WSI |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
- http://tftpd32.jounin.net/tftpd32_news.html
- http://tftpd32.jounin.net/tftpd32.html
- http://osvdb.org/show/osvdb/12898
- http://secway.org/advisory/ad20050108.txt
- http://www.wyse.com/serviceandsupport/support/WSB09-01.zip
- http://www.wyse.com/serviceandsupport/Wyse%20Security%20Bulletin%20WSB09-01.pdf
- http://www.theregister.co.uk/2009/07/10/wyse_remote_exploit_bugs/
- http://archives.neohapsis.com/archives/fulldisclosure/2009-07/0101.html
Acknowledgements
These vulnerabilities were analyzed and reported by Kevin Finisterre of Netragard/SNOsoft and Art Manion.
This document was written by Art Manion.
Other Information
CVE IDs: | CVE-2002-2226, CVE-2002-2237, CVE-2002-2353, CVE-2006-0328, CVE-2003-6141 |
Severity Metric: | 13.51 |
Date Public: | 2009-07-10 |
Date First Published: | 2009-11-19 |
Date Last Updated: | 2009-11-19 22:58 UTC |
Document Revision: | 54 |