¡¾·ì϶¹«¸æ¡¿CVE-2020-29491 Dell Wyse ThinOS RCE·ì϶
°ä²¼¹¦·ò 2020-12-220x00 ·ì϶¸ÅÊö
²úÆ·Ãû³Æ | CVE ID | Àà ÐÍ | ·ì϶µÈ¼¶ | Ô¶³ÌÀûÓà |
Dell Wyse Thin Clients | CVE-2020-29491 | RCE | ÑϳÁ | ÊÇ |
CVE-2020-29492 | RCE | ÑϳÁ | ÊÇ |
0x01 ·ì϶ÏêÇé

Thin clientsÊÇÒ»ÖÖ¾¹ýÓÅ»¯µÄÓ×ÐÍÍÆËã»ú£¬£¬£¬£¬£¬£¬£¬ÖØÒªÓÃÓÚÔ¶³Ì×ÀÃæ£¬£¬£¬£¬£¬£¬£¬ÒÔÏνӵ½ÆäËüϵͳ¡£¡£¡£¡£¡£¡£¡£¡£Wyse×Ô1990ÄêÒÔÀ´Ò»ÏòÔÚ¿ª·¢Thin clients£¬£¬£¬£¬£¬£¬£¬²¢ÓÚ2012Äê±»DellÊÕ¹º¡£¡£¡£¡£¡£¡£¡£¡£
2020Äê12ÔÂ21ÈÕ£¬£¬£¬£¬£¬£¬£¬Dell¹Ù·½°ä²¼°²È«²¼¸æ£¬£¬£¬£¬£¬£¬£¬Dell Wyse ThinOSÖдæÔÚÁ½¸öÑϳÁ·ì϶£¨CVE-2020-29491ºÍCVE-2020-29492£©¡£¡£¡£¡£¡£¡£¡£¡£
ÏêÇéÈçÏ£º
ThinOSÄܹ»Ô¶³ÌÊØ»¤£¬£¬£¬£¬£¬£¬£¬ÆäĬÈÏ·½Ê½ÊÇͨ¹ý±¾µØFTP·þÎñÆ÷ÏÂÔØÐµĹ̼þ¡¢Èí¼þ°üºÍÅäÖᣡ£¡£¡£¡£¡£¡£¡£
Dell½¨ÒéʹÓÃMicrosoft IIS´´½¨FTP·þÎñÆ÷£¬£¬£¬£¬£¬£¬£¬¶øºóÔÊÐí½Ó¼û¿Éͨ¹ýFTP·þÎñÆ÷½Ó¼ûµÄ¹Ì¼þ¡¢Èí¼þ°üºÍINIÎļþ¡£¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚFTPÅäÖÃΪ²»±ØÒªÍ´´¦£¨¡°ÄäÃû¡±Óû§£©£¬£¬£¬£¬£¬£¬£¬ÕâʹµÃFTP·þÎñÆ÷ÉÏÌØ¶¨µÄINIÎļþÄܹ»±»ÏνӵĿͻ§¶ËдÈë¡£¡£¡£¡£¡£¡£¡£¡£ÔÚFTP·þÎñÆ÷ÉÏÕÒµ½µÄ¹Ì¼þºÍ·¨Ê½°üÎļþÒÑÊðÃû£¬£¬£¬£¬£¬£¬£¬µ«ÓÃÓÚÅäÖõÄINIÎļþδÊðÃû¡£¡£¡£¡£¡£¡£¡£¡£Òò¶ø£¬£¬£¬£¬£¬£¬£¬ÍøÂçÉϵÄÈκι¥»÷Õß¶¼Äܹ»½Ó¼ûFTP·þÎñÆ÷²¢Åú¸ÄThin clientsµÄINIÅäÖÃÎļþ²¢±£Áô¡£¡£¡£¡£¡£¡£¡£¡£
´Ë±í£¬£¬£¬£¬£¬£¬£¬¼´±ãÉèÖÃÁËÍ´´¦£¬£¬£¬£¬£¬£¬£¬ËüÃÇÒ²½«ÔÚ´óÁ¿¿Í»§¶ËÖ®¼ä¹²Ïí£¬£¬£¬£¬£¬£¬£¬´Ó¶øÔÊÐíËüÃǸü¸Ä±Ë´ËµÄINIÅäÖÃÎļþ¡£¡£¡£¡£¡£¡£¡£¡£
µ±Dell WyseÉ豸Ïνӵ½FTP·þÎñÆ÷ʱ£¬£¬£¬£¬£¬£¬£¬Ëü»áÒÔ¡°{username}.INI¡±µÄ´ó¾ÖËÑË÷INIÎļþ£¬£¬£¬£¬£¬£¬£¬ÆäÖÐ{username}½«´úÌæÎªÖÕ¶ËʹÓõÄÓû§Ãû¡£¡£¡£¡£¡£¡£¡£¡£
ÈôÊÇÕâ¸öINIÎļþ´æÔÚ£¬£¬£¬£¬£¬£¬£¬É豸½«´ÓÖмÓÔØÅäÖᣡ£¡£¡£¡£¡£¡£¡£ÓÉÓÚ¸ÃÎļþ¿Éд£¬£¬£¬£¬£¬£¬£¬Òò¶ø¹¥»÷ÕßÄܹ»Åú¸ÄËüÀ´Åú¸ÄÓû§µÄÅäÖ㬣¬£¬£¬£¬£¬£¬×îÖÕÄܹ»ÔÚÖ¸±êϵͳÉÏÔ¶³ÌÖ´ÐдúÂë¡£¡£¡£¡£¡£¡£¡£¡£
Dell Wyse ThinOS ĬÈÏÅäÖÃÃýÎó·ì϶£¨CVE-2020-29491£©
¸Ã·ì϶ÊDz»°²È«µÄĬÈÏÅäÖÃÔì³ÉµÄ£¬£¬£¬£¬£¬£¬£¬ÆäCVSSÆÀ·ÖΪ10.0·Ö¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÄܹ»Í¨¹ýÀûÓô˷ì϶À´½Ó¼ûÖ¸±êϵͳÉϵÄÃô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£
Dell Wyse ThinOS ĬÈÏÅäÖÃÃýÎó·ì϶£¨CVE-2020-29492£©
¸Ã·ì϶ÊDz»°²È«µÄĬÈÏÅäÖÃÔì³ÉµÄ£¬£¬£¬£¬£¬£¬£¬ÆäCVSSÆÀ·ÖΪ10.0·Ö¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷ÕßÄܹ»Í¨¹ýÀûÓô˷ì϶À´½Ó¼û¿ÉдÎļþ²¢Åú¸ÄÖ¸±êϵͳÉϵÄThin clientsµÄÅäÖᣡ£¡£¡£¡£¡£¡£¡£
Ó°ÏìÁìÓò£º
Dell Wyse ThinOS 8.6 MR8֮ǰµÄ°æ±¾
½ØÖ¹Ä¿Ç°£¬£¬£¬£¬£¬£¬£¬Í¨¹ýZoomeyeËÑË÷£¬£¬£¬£¬£¬£¬£¬È«Çò»òÐíÓÐ400¶àÍò¸öDell Wyse Thin clients¡£¡£¡£¡£¡£¡£¡£¡£

0x02 ´ëÖý¨Òé
ĿǰDellÒѾ°ä²¼ÁËÓйذ²È«¸üУ¬£¬£¬£¬£¬£¬£¬½¨Òé²Î¿¼Ï±íʵʱ½¨¸´¡£¡£¡£¡£¡£¡£¡£¡£
²úÆ· | ÊÜÓ°Ïì°æ±¾ | ½¨¸´°æ±¾ | Á´½Ó |
Dell Wyse 3040 Thin Client (ENG) | 8.6 MR8֮ǰµÄ°æ±¾ | 8.6 MR8 | https://www.dell.com/support/home/drivers/driversdetails?driverid=cxv3j&oscode=thn80&productcode=wyse-3040-thin-client |
Dell Wyse 3040 Thin Client (JPN) | 8.6 MR8֮ǰµÄ°æ±¾ | 8.6 MR8 | https://www.dell.com/support/home/drivers/driversdetails?driverid=vry7h&oscode=thn80&productcode=wyse-3040-thin-client |
Dell Wyse 3040 Thin Client with PCoIP (ENG) | 8.6 MR8֮ǰµÄ°æ±¾ | 8.6 MR8 | https://www.dell.com/support/home/drivers/driversdetails?driverid=5dx5y&oscode=thn8p&productcode=wyse-3040-thin-client |
Dell Wyse 3040 Thin Client with PCoIP (JPN) | 8.6 MR8֮ǰµÄ°æ±¾ | 8.6 MR8 | https://www.dell.com/support/home/drivers/driversdetails?driverid=tk93y&oscode=thn80&productcode=wyse-3040-thin-client |
Dell Wyse 5010 Thin Client (ENG) | 8.6 MR8֮ǰµÄ°æ±¾ | 8.6 MR8 | https://www.dell.com/support/home/drivers/driversdetails?driverid=0ynjw&oscode=thn80&productcode=wyse-5010tc-series |
Dell Wyse 5010 Thin Client (JPN) | 8.6 MR8֮ǰµÄ°æ±¾ | 8.6 MR8 | https://www.dell.com/support/home/drivers/driversdetails?driverid=1nkvx&oscode=thn80&productcode=wyse-5010tc-series |
Dell Wyse 5010 Thin Client with PCoIP (ENG) | 8.6 MR8֮ǰµÄ°æ±¾ | 8.6 MR8 | https://www.dell.com/support/home/drivers/driversdetails?driverid=kv85h&oscode=thn8p&productcode=wyse-5010tc-series |
Dell Wyse 5010 Thin Client with PCoIP (JPN) | 8.6 MR8֮ǰµÄ°æ±¾ | 8.6 MR8 | https://www.dell.com/support/home/drivers/driversdetails?driverid=r39r6&oscode=thn8p&productcode=wyse-5010tc-series |
Dell Wyse 5040 Thin Client (ENG) | 8.6 MR8֮ǰµÄ°æ±¾ | 8.6 MR8 | https://www.dell.com/support/home/en-in/drivers/driversdetails?driverid=0ynjw&oscode=thn80&productcode=wyse-5010tc-series |
Dell Wyse 5040 Thin Client (JPN) | 8.6 MR8֮ǰµÄ°æ±¾ | 8.6 MR8 | https://www.dell.com/support/home/drivers/driversdetails?driverid=1nkvx&oscode=thn80&productcode=wyse-5010tc-series |
Dell Wyse 5040 Thin Client with PCoIP (ENG) | 8.6 MR8֮ǰµÄ°æ±¾ | 8.6 MR8 | https://www.dell.com/support/home/drivers/driversdetails?driverid=kv85h&oscode=thn8p&productcode=wyse-5010tc-series |
Dell Wyse 5040 Thin Client with PCoIP (JPN) | 8.6 MR8֮ǰµÄ°æ±¾ | 8.6 MR8 | https://www.dell.com/support/home/drivers/driversdetails?driverid=r39r6&oscode=thn8p&productcode=wyse-5010tc-series |
Dell Wyse 5060 Thin Client (ENG) | 8.6 MR8֮ǰµÄ°æ±¾ | 8.6 MR8 | https://www.dell.com/support/home/drivers/driversdetails?driverid=rdr2t&oscode=thn80&productcode=wyse-5060-thin-client |
Dell Wyse 5060 Thin Client (JPN) | 8.6 MR8֮ǰµÄ°æ±¾ | 8.6 MR8 | https://www.dell.com/support/home/drivers/driversdetails?driverid=8998g&oscode=thn80&productcode=wyse-5060-thin-client |
Dell Wyse 5060 Thin Client with PCoIP (ENG) | 8.6 MR8֮ǰµÄ°æ±¾ | 8.6 MR8 | https://www.dell.com/support/home/drivers/driversdetails?driverid=8jxd2&oscode=thn8p&productcode=wyse-5060-thin-client |
Dell Wyse 5060 Thin Client with PCoIP (JPN) | 8.6 MR8֮ǰµÄ°æ±¾ | 8.6 MR8 | https://www.dell.com/support/home/drivers/driversdetails?driverid=gwy2y&oscode=thn8p&productcode=wyse-5060-thin-client |
Dell Wyse 5070 Thin Client (ENG) | 8.6 MR8֮ǰµÄ°æ±¾ | 8.6 MR8 | https://www.dell.com/support/home/drivers/driversdetails?driverid=02vmh&oscode=thn80&productcode=wyse-5070-thin-client |
Dell Wyse 5070 Thin Client (JPN) | 8.6 MR8֮ǰµÄ°æ±¾ | 8.6 MR8 | https://www.dell.com/support/home/drivers/driversdetails?driverid=j0dx4&oscode=thn80&productcode=wyse-5070-thin-client |
Dell Wyse 5070 Thin Client with PCoIP (ENG) | 8.6 MR8֮ǰµÄ°æ±¾ | 8.6 MR8 | https://www.dell.com/support/home/drivers/driversdetails?driverid=rj0yw&oscode=thn8p&productcode=wyse-5070-thin-client |
Dell Wyse 5070 Thin Client with PCoIP (JPN) | 8.6 MR8֮ǰµÄ°æ±¾ | 8.6 MR8 | https://www.dell.com/support/home/drivers/driversdetails?driverid=kj6mp&oscode=thn8p&productcode=wyse-5070-thin-client |
Dell Wyse 5470 AIO Thin Client (ENG) | 8.6 MR8֮ǰµÄ°æ±¾ | 8.6 MR8 | https://www.dell.com/support/home/drivers/driversdetails?driverid=x38ch&oscode=thn80&productcode=wyse-5470-aio |
Dell Wyse 5470 AIO Thin Client (JPN) | 8.6 MR8֮ǰµÄ°æ±¾ | 8.6 MR8 | https://www.dell.com/support/home/drivers/driversdetails?driverid=4nx45&oscode=thn80&productcode=wyse-5470-aio |
Dell Wyse 5470 AIO Thin Client with PCoIP (ENG) | 8.6 MR8֮ǰµÄ°æ±¾ | 8.6 MR8 | https://www.dell.com/support/home/drivers/driversdetails?driverid=fw8tm&oscode=thn8p&productcode=wyse-5470-aio |
Dell Wyse 5470 AIO Thin Client with PCoIP (JPN) | 8.6 MR8֮ǰµÄ°æ±¾ | 8.6 MR8 | https://www.dell.com/support/home/drivers/driversdetails?driverid=m65dv&oscode=thn8p&productcode=wyse-5470-aio |
Dell Wyse 5470 Thin Client (ENG) | 8.6 MR8֮ǰµÄ°æ±¾ | 8.6 MR8 | https://www.dell.com/support/home/drivers/driversdetails?driverid=c0ncw&oscode=thn80&productcode=wyse-5470-mobile-thin-client |
Dell Wyse 5470 Thin Client (JPN) | 8.6 MR8֮ǰµÄ°æ±¾ | 8.6 MR8 | https://www.dell.com/support/home/drivers/driversdetails?driverid=4hjk3&oscode=thn80&productcode=wyse-5470-mobile-thin-client |
Dell Wyse 5470 Thin Client with PCoIP (ENG) | 8.6 MR8֮ǰµÄ°æ±¾ | 8.6 MR8 | https://www.dell.com/support/home/drivers/driversdetails?driverid=y3m10&oscode=thn8p&productcode=wyse-5470-mobile-thin-client |
Dell Wyse 5470 Thin Client with PCoIP (JPN) | 8.6 MR8֮ǰµÄ°æ±¾ | 8.6 MR8 | https://www.dell.com/support/home/drivers/driversdetails?driverid=ffwk9&oscode=thn8p&productcode=wyse-5470-mobile-thin-client |
Dell Wyse 7010 Thin Client (ENG) | 8.6 MR8֮ǰµÄ°æ±¾ | 8.6 MR8 | https://www.dell.com/support/home/drivers/driversdetails?driverid=0ynjw&oscode=thn80&productcode=wyse-5010tc-series |
Dell Wyse 7010 thin client (JPN) | 8.6 MR8֮ǰµÄ°æ±¾ | 8.6 MR8 | https://www.dell.com/support/home/drivers/driversdetails?driverid=1nkvx&oscode=thn80&productcode=wyse-5010tc-series |
»º½â´ëÊ©£º
l ʹÓð²È«ºÍ̸¡£¡£¡£¡£¡£¡£¡£¡£ÈçʹÓÃHTTPS°ü°ìHTTP»òFTP£¬£¬£¬£¬£¬£¬£¬²¢È·±£Îļþ·þÎñÆ÷½Ó¼ûȨÏÞÉèÖÃΪֻ¶Á¡£¡£¡£¡£¡£¡£¡£¡£
l ʹÓÃWyse Management Suite¶ø²»ÊÇÎļþ·þÎñÆ÷À´½øÐÐÉ豸ÅäÖᣡ£¡£¡£¡£¡£¡£¡£Wyse Management SuiteͨѶǿÔìÖ´ÐÐHTTPSºÍ̸£¬£¬£¬£¬£¬£¬£¬ËùÓÐÅäÖö¼´æ´¢ÔÚ°²È«µÄ·þÎñÆ÷Êý¾Ý¿âÖУ¬£¬£¬£¬£¬£¬£¬¶ø²»ÊÇ´æ´¢Ôڿɱà×ëµÄÅäÖÃÎļþÖС£¡£¡£¡£¡£¡£¡£¡£
l ʹÓÃThinOS 9µÄDell Wyse Management Suite¡£¡£¡£¡£¡£¡£¡£¡£ThinOS 9¿Í»§¶Ë²»Ö§³ÖÎļþ·þÎñÆ÷ÅäÖ㬣¬£¬£¬£¬£¬£¬Òò¶ø¸Ã·ì϶ÎÞ·¨ÀûÓᣡ£¡£¡£¡£¡£¡£¡£
0x03 ²Î¿¼Á´½Ó
https://www.dell.com/support/kbdoc/en-us/000180768/dsa-2020-281
https://www.bleepingcomputer.com/news/security/critical-bugs-in-dell-wyse-thinos-allow-thin-client-take-over/
https://www.cybermdx.com/vulnerability-research-disclosures/dell-wyse-thin-client-vulnerability
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-29492
0x04 ¹¦·òÏß
2020-12-21 Dell°ä²¼°²È«²¼¸æ
2020-12-22 VSRC°ä²¼°²È«¹«¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/



¾©¹«Íø°²±¸11010802024551ºÅ