Blog | G5 Cyber Security

Dell Wyse ThinOS flaws allow hacking think clients

Multiple Dell Wyse thin client models are affected by critical vulnerabilities that could be exploited by a remote attacker to take over the devices. Cybersecurity firm CyberMDX discovered that it is possible to access the thin clients via FTP without providing credentials, using anonymous user. An INI file on the FTP server should be writeable for the connecting clients. Even if credentials were set, they would be shared across a large fleet of clients, allowing them to alter each others INI configuration files.”]

Source: https://securityaffairs.co/wordpress/112520/hacking/dell-wyse-thinos-flaws.html

Exit mobile version