Overview
Wyse Device Manager (WDM) Server and HAgent contain several vulnerabilities. An attacker with network access to WDM components could execute arbitrary code on vulnerable systems.
Description
Wyse Device Manager (WDM, formerly known as Wyse Rapport) manages thin clients. Part of the server component (HServer) is implemented as an ISAPI filter on the Microsoft Windows Internet Information Server (IIS) platform. The client component (HAgent) runs as a service on Microsoft Windows systems. WDM components contain several vulnerabilities:
|
Impact
An attacker with network access to WDM components could execute arbitrary code on a vulnerable system. The attacker could also execute unauthenticated management commands on a system running HAgent. |
Solution
Please see Wyse Security Bulletin WSB09-01. |
Enable HTTPS |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
- http://osvdb.org/show/osvdb/55808
- http://www.wyse.com/serviceandsupport/support/WSB09-01.zip
- http://www.wyse.com/serviceandsupport/Wyse%20Security%20Bulletin%20WSB09-01.pdf
- http://www.theregister.co.uk/2009/07/10/wyse_remote_exploit_bugs/
- http://archives.neohapsis.com/archives/fulldisclosure/2009-07/0101.html
Acknowledgements
These vulnerabilities were analyzed and reported by Kevin Finisterre of Netragard/SNOsoft.
This document was written by Art Manion.
Other Information
CVE IDs: | CVE-2009-0693, CVE-2009-0695 |
Severity Metric: | 13.51 |
Date Public: | 2009-07-10 |
Date First Published: | 2009-10-13 |
Date Last Updated: | 2009-10-16 04:27 UTC |
Document Revision: | 24 |