Article Number: 000180768
Critical
Proprietary Code CVE(s) | Description | CVSS Base Score | CVSS Vector String |
CVE-2020-29491 | Dell Wyse ThinOS 8.6 and prior versions contain an insecure default configuration vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability to gain access to the sensitive information on the local network, leading to the potential compromise of impacted thin clients. | 10.0 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
CVE-2020-29492 | Dell Wyse ThinOS 8.6 and prior versions contain an insecure default configuration vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability to access the writable file and manipulate the configuration of any target specific station. | 10.0 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Proprietary Code CVE(s) | Description | CVSS Base Score | CVSS Vector String |
CVE-2020-29491 | Dell Wyse ThinOS 8.6 and prior versions contain an insecure default configuration vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability to gain access to the sensitive information on the local network, leading to the potential compromise of impacted thin clients. | 10.0 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
CVE-2020-29492 | Dell Wyse ThinOS 8.6 and prior versions contain an insecure default configuration vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability to access the writable file and manipulate the configuration of any target specific station. | 10.0 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Product | Affected Version(s) | Updated Version(s) | Link to Update |
Dell Wyse 3040 Thin Client (ENG) | Versions prior to 8.6 MR8 where the Client is receiving configurations from a remote file server over an insecure protocol | 8.6 MR8 | Dell Wyse 3040 Thin Client (ENG) |
Dell Wyse 3040 Thin Client (JPN) | Versions prior to 8.6 MR8 where the Client is receiving configurations from a remote file server over an insecure protocol |
8.6 MR8 | Dell Wyse 3040 Thin Client (JPN) |
Dell Wyse 3040 Thin Client with PCoIP (ENG) | Versions prior to 8.6 MR8 where the Client is receiving configurations from a remote file server over an insecure protocol |
8.6 MR8 | Dell Wyse 3040 Thin Client with PCoIP (ENG) |
Dell Wyse 3040 Thin Client with PCoIP (JPN) | Versions prior to 8.6 MR8 where the Client is receiving configurations from a remote file server over an insecure protocol |
8.6 MR8 | Dell Wyse 3040 Thin Client with PCoIP (JPN) |
Dell Wyse 5010 Thin Client (ENG) | Versions prior to 8.6 MR8 where the Client is receiving configurations from a remote file server over an insecure protocol | 8.6 MR8 | Dell Wyse 5010 Thin Client (ENG) |
Dell Wyse 5010 Thin Client (JPN) | Versions prior to 8.6 MR8 where the Client is receiving configurations from a remote file server over an insecure protocol | 8.6 MR8 | Dell Wyse 5010 Thin Client (JPN) |
Dell Wyse 5010 Thin Client with PCoIP (ENG) | Versions prior to 8.6 MR8 where the Client is receiving configurations from a remote file server over an insecure protocol |
8.6 MR8 | Dell Wyse 5010 Thin Client with PCoIP (ENG) |
Dell Wyse 5010 Thin Client with PCoIP (JPN) | Versions prior to 8.6 MR8 where the Client is receiving configurations from a remote file server over an insecure protocol |
8.6 MR8 | Dell Wyse 5010 Thin Client with PCoIP (JPN) |
Dell Wyse 5040 Thin Client (ENG) | Versions prior to 8.6 MR8 where the Client is receiving configurations from a remote file server over an insecure protocol | 8.6 MR8 | Dell Wyse 5040 Thin Client (ENG) |
Dell Wyse 5040 Thin Client (JPN) | Versions prior to 8.6 MR8 where the Client is receiving configurations from a remote file server over an insecure protocol | 8.6 MR8 | Dell Wyse 5040 Thin Client (JPN) |
Dell Wyse 5040 Thin Client with PCoIP (ENG) | Versions prior to 8.6 MR8 where the Client is receiving configurations from a remote file server over an insecure protocol |
8.6 MR8 | Dell Wyse 5040 Thin Client with PCoIP (ENG) |
Dell Wyse 5040 Thin Client with PCoIP (JPN) | Versions prior to 8.6 MR8 where the Client is receiving configurations from a remote file server over an insecure protocol |
8.6 MR8 | Dell Wyse 5040 Thin Client with PCoIP (JPN) |
Dell Wyse 5060 Thin Client (ENG) | Versions prior to 8.6 MR8 where the Client is receiving configurations from a remote file server over an insecure protocol |
8.6 MR8 | Dell Wyse 5060 Thin Client (ENG) |
Dell Wyse 5060 Thin Client (JPN) | Versions prior to 8.6 MR8 where the Client is receiving configurations from a remote file server over an insecure protocol | 8.6 MR8 | Dell Wyse 5060 Thin Client (JPN) |
Dell Wyse 5060 Thin Client with PCoIP (ENG) | Versions prior to 8.6 MR8 where the Client is receiving configurations from a remote file server over an insecure protocol |
8.6 MR8 | Dell Wyse 5060 Thin Client with PCoIP (ENG) |
Dell Wyse 5060 Thin Client with PCoIP (JPN) | Versions prior to 8.6 MR8 where the Client is receiving configurations from a remote file server over an insecure protocol |
8.6 MR8 | Dell Wyse 5060 Thin Client with PCoIP (JPN) |
Dell Wyse 5070 Thin Client (ENG) | Versions prior to 8.6 MR8 where the Client is receiving configurations from a remote file server over an insecure protocol | 8.6 MR8 | Dell Wyse 5070 Thin Client (ENG) |
Dell Wyse 5070 Thin Client (JPN) | Versions prior to 8.6 MR8 where the Client is receiving configurations from a remote file server over an insecure protocol | 8.6 MR8 | Dell Wyse 5070 Thin Client (JPN) |
Dell Wyse 5070 Thin Client with PCoIP (ENG) | Versions prior to 8.6 MR8 where the Client is receiving configurations from a remote file server over an insecure protocol |
8.6 MR8 | Dell Wyse 5070 Thin Client with PCoIP (ENG) |
Dell Wyse 5070 Thin Client with PCoIP (JPN) | Versions prior to 8.6 MR8 where the Client is receiving configurations from a remote file server over an insecure protocol |
8.6 MR8 | Dell Wyse 5070 Thin Client with PCoIP (JPN) |
Dell Wyse 5470 AIO Thin Client (ENG) | Versions prior to 8.6 MR8 where the Client is receiving configurations from a remote file server over an insecure protocol |
8.6 MR8 | Dell Wyse 5470 AIO Thin Client (ENG) |
Dell Wyse 5470 AIO Thin Client (JPN) | Versions prior to 8.6 MR8 where the Client is receiving configurations from a remote file server over an insecure protocol |
8.6 MR8 | Dell Wyse 5470 AIO Thin Client (JPN) |
Dell Wyse 5470 AIO Thin Client with PCoIP (ENG) | Versions prior to 8.6 MR8 where the Client is receiving configurations from a remote file server over an insecure protocol |
8.6 MR8 | Dell Wyse 5470 AIO Thin Client with PCoIP (ENG) |
Dell Wyse 5470 AIO Thin Client with PCoIP (JPN) | Versions prior to 8.6 MR8 where the Client is receiving configurations from a remote file server over an insecure protocol |
8.6 MR8 | Dell Wyse 5470 AIO Thin Client with PCoIP (JPN) |
Dell Wyse 5470 Thin Client (ENG) | Versions prior to 8.6 MR8 where the Client is receiving configurations from a remote file server over an insecure protocol | 8.6 MR8 | Dell Wyse 5470 Thin Client (ENG) |
Dell Wyse 5470 Thin Client (JPN) | Versions prior to 8.6 MR8 where the Client is receiving configurations from a remote file server over an insecure protocol | 8.6 MR8 | Dell Wyse 5470 Thin Client (JPN) |
Dell Wyse 5470 Thin Client with PCoIP (ENG) | Versions prior to 8.6 MR8 where the Client is receiving configurations from a remote file server over an insecure protocol | 8.6 MR8 | Dell Wyse 5470 Thin Client with PCoIP (ENG) |
Dell Wyse 5470 Thin Client with PCoIP (JPN) | Versions prior to 8.6 MR8 where the Client is receiving configurations from a remote file server over an insecure protocol |
8.6 MR8 | Dell Wyse 5470 Thin Client with PCoIP (JPN) |
Dell Wyse 7010 Thin Client (ENG) | Versions prior to 8.6 MR8 where the Client is receiving configurations from a remote file server over an insecure protocol | 8.6 MR8 | Dell Wyse 7010 Thin Client (ENG) |
Dell Wyse 7010 thin client (JPN) | Versions prior to 8.6 MR8 where the Client is receiving configurations from a remote file server over an insecure protocol | 8.6 MR8 | Dell Wyse 7010 thin client (JPN) |
Product | Affected Version(s) | Updated Version(s) | Link to Update |
Dell Wyse 3040 Thin Client (ENG) | Versions prior to 8.6 MR8 where the Client is receiving configurations from a remote file server over an insecure protocol | 8.6 MR8 | Dell Wyse 3040 Thin Client (ENG) |
Dell Wyse 3040 Thin Client (JPN) | Versions prior to 8.6 MR8 where the Client is receiving configurations from a remote file server over an insecure protocol |
8.6 MR8 | Dell Wyse 3040 Thin Client (JPN) |
Dell Wyse 3040 Thin Client with PCoIP (ENG) | Versions prior to 8.6 MR8 where the Client is receiving configurations from a remote file server over an insecure protocol |
8.6 MR8 | Dell Wyse 3040 Thin Client with PCoIP (ENG) |
Dell Wyse 3040 Thin Client with PCoIP (JPN) | Versions prior to 8.6 MR8 where the Client is receiving configurations from a remote file server over an insecure protocol |
8.6 MR8 | Dell Wyse 3040 Thin Client with PCoIP (JPN) |
Dell Wyse 5010 Thin Client (ENG) | Versions prior to 8.6 MR8 where the Client is receiving configurations from a remote file server over an insecure protocol | 8.6 MR8 | Dell Wyse 5010 Thin Client (ENG) |
Dell Wyse 5010 Thin Client (JPN) | Versions prior to 8.6 MR8 where the Client is receiving configurations from a remote file server over an insecure protocol | 8.6 MR8 | Dell Wyse 5010 Thin Client (JPN) |
Dell Wyse 5010 Thin Client with PCoIP (ENG) | Versions prior to 8.6 MR8 where the Client is receiving configurations from a remote file server over an insecure protocol |
8.6 MR8 | Dell Wyse 5010 Thin Client with PCoIP (ENG) |
Dell Wyse 5010 Thin Client with PCoIP (JPN) | Versions prior to 8.6 MR8 where the Client is receiving configurations from a remote file server over an insecure protocol |
8.6 MR8 | Dell Wyse 5010 Thin Client with PCoIP (JPN) |
Dell Wyse 5040 Thin Client (ENG) | Versions prior to 8.6 MR8 where the Client is receiving configurations from a remote file server over an insecure protocol | 8.6 MR8 | Dell Wyse 5040 Thin Client (ENG) |
Dell Wyse 5040 Thin Client (JPN) | Versions prior to 8.6 MR8 where the Client is receiving configurations from a remote file server over an insecure protocol | 8.6 MR8 | Dell Wyse 5040 Thin Client (JPN) |
Dell Wyse 5040 Thin Client with PCoIP (ENG) | Versions prior to 8.6 MR8 where the Client is receiving configurations from a remote file server over an insecure protocol |
8.6 MR8 | Dell Wyse 5040 Thin Client with PCoIP (ENG) |
Dell Wyse 5040 Thin Client with PCoIP (JPN) | Versions prior to 8.6 MR8 where the Client is receiving configurations from a remote file server over an insecure protocol |
8.6 MR8 | Dell Wyse 5040 Thin Client with PCoIP (JPN) |
Dell Wyse 5060 Thin Client (ENG) | Versions prior to 8.6 MR8 where the Client is receiving configurations from a remote file server over an insecure protocol |
8.6 MR8 | Dell Wyse 5060 Thin Client (ENG) |
Dell Wyse 5060 Thin Client (JPN) | Versions prior to 8.6 MR8 where the Client is receiving configurations from a remote file server over an insecure protocol | 8.6 MR8 | Dell Wyse 5060 Thin Client (JPN) |
Dell Wyse 5060 Thin Client with PCoIP (ENG) | Versions prior to 8.6 MR8 where the Client is receiving configurations from a remote file server over an insecure protocol |
8.6 MR8 | Dell Wyse 5060 Thin Client with PCoIP (ENG) |
Dell Wyse 5060 Thin Client with PCoIP (JPN) | Versions prior to 8.6 MR8 where the Client is receiving configurations from a remote file server over an insecure protocol |
8.6 MR8 | Dell Wyse 5060 Thin Client with PCoIP (JPN) |
Dell Wyse 5070 Thin Client (ENG) | Versions prior to 8.6 MR8 where the Client is receiving configurations from a remote file server over an insecure protocol | 8.6 MR8 | Dell Wyse 5070 Thin Client (ENG) |
Dell Wyse 5070 Thin Client (JPN) | Versions prior to 8.6 MR8 where the Client is receiving configurations from a remote file server over an insecure protocol | 8.6 MR8 | Dell Wyse 5070 Thin Client (JPN) |
Dell Wyse 5070 Thin Client with PCoIP (ENG) | Versions prior to 8.6 MR8 where the Client is receiving configurations from a remote file server over an insecure protocol |
8.6 MR8 | Dell Wyse 5070 Thin Client with PCoIP (ENG) |
Dell Wyse 5070 Thin Client with PCoIP (JPN) | Versions prior to 8.6 MR8 where the Client is receiving configurations from a remote file server over an insecure protocol |
8.6 MR8 | Dell Wyse 5070 Thin Client with PCoIP (JPN) |
Dell Wyse 5470 AIO Thin Client (ENG) | Versions prior to 8.6 MR8 where the Client is receiving configurations from a remote file server over an insecure protocol |
8.6 MR8 | Dell Wyse 5470 AIO Thin Client (ENG) |
Dell Wyse 5470 AIO Thin Client (JPN) | Versions prior to 8.6 MR8 where the Client is receiving configurations from a remote file server over an insecure protocol |
8.6 MR8 | Dell Wyse 5470 AIO Thin Client (JPN) |
Dell Wyse 5470 AIO Thin Client with PCoIP (ENG) | Versions prior to 8.6 MR8 where the Client is receiving configurations from a remote file server over an insecure protocol |
8.6 MR8 | Dell Wyse 5470 AIO Thin Client with PCoIP (ENG) |
Dell Wyse 5470 AIO Thin Client with PCoIP (JPN) | Versions prior to 8.6 MR8 where the Client is receiving configurations from a remote file server over an insecure protocol |
8.6 MR8 | Dell Wyse 5470 AIO Thin Client with PCoIP (JPN) |
Dell Wyse 5470 Thin Client (ENG) | Versions prior to 8.6 MR8 where the Client is receiving configurations from a remote file server over an insecure protocol | 8.6 MR8 | Dell Wyse 5470 Thin Client (ENG) |
Dell Wyse 5470 Thin Client (JPN) | Versions prior to 8.6 MR8 where the Client is receiving configurations from a remote file server over an insecure protocol | 8.6 MR8 | Dell Wyse 5470 Thin Client (JPN) |
Dell Wyse 5470 Thin Client with PCoIP (ENG) | Versions prior to 8.6 MR8 where the Client is receiving configurations from a remote file server over an insecure protocol | 8.6 MR8 | Dell Wyse 5470 Thin Client with PCoIP (ENG) |
Dell Wyse 5470 Thin Client with PCoIP (JPN) | Versions prior to 8.6 MR8 where the Client is receiving configurations from a remote file server over an insecure protocol |
8.6 MR8 | Dell Wyse 5470 Thin Client with PCoIP (JPN) |
Dell Wyse 7010 Thin Client (ENG) | Versions prior to 8.6 MR8 where the Client is receiving configurations from a remote file server over an insecure protocol | 8.6 MR8 | Dell Wyse 7010 Thin Client (ENG) |
Dell Wyse 7010 thin client (JPN) | Versions prior to 8.6 MR8 where the Client is receiving configurations from a remote file server over an insecure protocol | 8.6 MR8 | Dell Wyse 7010 thin client (JPN) |
Below are best practices to address this issue. Dell recommends customers implement one of the following:
Dell would like to thank Prof. Gil David and Elad Luz of CyberMDX for reporting this vulnerability.
Revision | Date | Description |
1.0 | 2020-12-21 | Initial Release |
Dell Security Advisories and Notices
Dell Vulnerability Response Policy
CVSS Scoring Guide
Wyse ThinOS
17 Feb 2021
2
Dell Security Advisory