DNS and DHCP Vulnerability with Wyse ThinOS 8.6

Summary: Learn about the best practices to prevent a Wyse ThinOS 8.6 vulnerability with DNS and DHCP.

This article applies to This article does not apply to This article is not tied to any specific product. Not all product versions are identified in this article.

Symptoms

Wyse ThinOS 8.6 may experience a vulnerability with DNS and DHCP.


Affected Operating Systems:

  • ThinOS 8.6

A potential vulnerability has been reported regarding ThinOS 8.6 clients being compromised by altering DHCP options. This can allow reception of client configurations and certificates from a rogue management server or redirect VDI communications to a rogue VDI server environment. This does not allow execution of malicious code on the Wyse ThinOS client, nor does it allow alteration of the ThinOS client operating system or partner components. ThinOS 8.6 clients that are properly secured during the initial configuration process from a management server should not encounter this issue. In addition, this vulnerability may be used to compromise other endpoint devices (Dell or otherwise) running Linux and Windows operating systems.

Customer VDI and management environment (server) communications using secure https (SSL) connections with a certificate check are not compromised. Changing the client certificate alone results in SSL failures when attempting SSL connections to customer servers enforcing certificate validation during the SSL connection process. This exploit only allows communications to be compromised by redirecting them to rogue VDI or management servers under the control of the individual attempting the exploit.

This issue may occur when:

  1. A rogue DNS or DHCP server has a rogue Wyse Management Suite or file server URL configured in its configuration options.
  2. Upon first-time bootup, thin clients discover the rogue Wyse Management Suite or file server URLs to receive configurations.
  3. The rogue file server or Wyse Management Suite server then provides manipulative configurations and client certificates. Alternatively, it may redirect to rogue VDI server environments.

Cause

What is the root cause?

Unsecure DNS and DHCP protocols.

What is the impact?

ThinOS 8.6 clients that get compromised by communicating to a rogue Wyse Management Suite or file server would possibly:

  • Read unexpected configurations and certificates.
  • Point to unexpected VDI server environments.

However, this impact does not allow a malicious code to be run inside a ThinOS 8.6 thin client.

Resolution

How is this vulnerability mitigated?

From ThinOS build 8.6_710 and later, the following thin client discovery configurations INIs are disabled after receiving the initial configuration from Wyse Management Suite. This is default behavior unless explicitly enabled by a user in the INI.

SecurityPolicy=Full/warning/low DNSFileServerDiscover=No

This disables DNSFileServerDiscover, and does not contact the reserved FTP server after initial configurations are received.

WMSEnable=Yes Discover=No

This disables management server discovery from DNS records. The thin client ignores any alterations of management server URLs in DNS records after initial configurations are received.

DHCPOptionsRemap=yes Discover=No

This disables file server or management server discovery from DHCP options. Any alterations of file server or management server URLs in DHCP options will be ignored after initial configurations are received.

Recommendations for secure connectivity

ThinOS 8.6 customers are recommended to follow the following ThinOS 8.6 best practices to prevent this potential vulnerability:

  • Ensure all customer VDI and management servers use https (SSL) communications that enforce strict certificate validation.
  • Ensure the management server (from which ThinOS receives device configurations) enforces ThinOS certificate validation when connecting to management servers and VDI servers. To do this, set INI (WMS Advanced) settings to SecurityPolicy=Full after initial configurations are received from Wyse Management Suite.

Affected Products

Dell ThinOS
Article Properties
Article Number: 000191164
Article Type: Solution
Last Modified: 22 Aug 2025
Version:  7
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.