Dell Wyse Thin Client scores two perfect 10 security flaws
- Reference: 1608570010
- News link: https://www.theregister.co.uk/2020/12/21/dell_wyse_thin_client_scores/
- Source link:
CVE-2020-29491 and CVE-2020-29492 are both critical flaws, managing a perfect (although unwelcome) CVSS score of 10 out of 10. The vulnerabilities, which affect all Dell Wyse Thin Clients running ThinOS versions 8.6 or earlier, allow more or less anyone to remotely run malicious code and to access arbitrary files on vulnerable devices.
The issues were identified by security biz CyberMDX, which said in its disclosure, "The profound potential impact of these vulnerabilities coupled with the relative ease of exploitation is what makes them so critical."
Dell Wyse Thin Clients allow companies to provide employees with access to applications via stripped-down, cloud-connected client machines that do most of their computing remotely on the server. In theory, this reduces costs, improves device manageability, and enhances security.
As CyberMDX explains in its report, while ThinOS can be remotely maintained, Dell recommends creating a local FTP server using Microsoft IIS and then setting up access to firmware, software packages, and INI configuration files.
The security biz points out that the FTP is set up for an "anonymous" user with no credentials. And while the firmware and packages on the FTP server have digital signatures, the INI configuration files do not. So anyone with access to them can alter them.
Not only are the INI files writable but this is by design – CyberMDX says there's a particular INI file on the FTP server that is supposed to be writable for connecting clients.
"Since there are no credentials, essentially anyone on the network can access the FTP server and modify that INI file holding configuration for the thin client devices," the CyberMDX advisory says, adding that even if credentials were set, they'd be shared across all the clients on the network, which would let them alter each other's INI files.
These INI files have a lot of parameters and altering them can open the door to bad things. Dell's guide
[1]PDF
for configuring INI file parameters goes on for 112 pages. According to CyberMDX, altering those values makes a variety of attack scenarios possible, including a full remote takeover of the VNC (Virtual Network Computing) software, leaking remote desktop credentials, and manipulating DNS settings.In the US alone, about 6000 companies and organizations use Dell Wyse Thin Clients, many of them healthcare organizations, the CyberMDX report says.
"We encourage customers to apply the remediations and follow the best practices described in the Dell Security Advisory ( [2]DSA-2020-281 )," a Dell spokesperson told The Register in an email. "The security of our products is critical to helping ensure our customers’ data and systems are protected."
Dell's spokesperson thanked Gil David and Elad Luz of CyberMDX for reporting the vulnerabilities. ®
Get our [3]Tech Resources
[1] https://topics-cdn.dell.com/pdf/wyse-5470-mobile-thin-client_Reference-Guide9_en-us.pdf
[2] https://www.dell.com/support/kbdoc/000180768
[3] https://whitepapers.theregister.com/
Good Job Dell!
According to Dell's website, "Wyse Thin Clients Accelerate your cloud strategy and enhance virtual workspaces with intelligent unified management and the ultimate security solutions."
Way to go Dell - a perfect 10 for 10 - definitely the ultimate security (security fauilure, that is)! Evidently security was part of the "fat" they removed to get to a "thin" client.
“Dude! You’re hacking a Dell!”
No further comment.
Re: “Dude! You’re hacking a Dell!”
It's hardly hacking when you are waved in and allowed to do whatever you like.
The Fools Mate of ...
Security!
An anonymous, world writable FTP server on IIS?!
I just have no words to describe this.
Unsurprising
Never liked ThinOS. If you're going to be running thin clients, then you should be running either the Windows Embedded variants or a proper Linux. Neither are especially difficult to manage, and both are better thought out than this mess.
Perfect 10? It goes up to 11. The stupid, that is.
I wondered why TF the clients needed write access to the server and it wasn't explained in either [1]CyberMDX or [2]Dell's reports.
In the referenced [3]Thin client reference guide , however, reveals all (p. 7, my emphasis):
7 {username}.ini Files must be Write-Enabled
All {username}.ini files must be write-enabled to allow the thin client to place the encrypted user passwords in the files.
At that point, I stopped reading.
[1] https://www.cybermdx.com/vulnerability-research-disclosures/dell-wyse-thin-client-vulnerability
[2] https://www.dell.com/support/kbdoc/en-au/000180768/dsa-2020-281
[3] https://topics-cdn.dell.com/pdf/wyse-5470-mobile-thin-client_Reference-Guide9_en-us.pdf
LOL
Wyse guys