¡¾Îó²îͨ¸æ¡¿CVE-2020-29491 Dell Wyse ThinOS RCEÎó²î
Ðû²¼Ê±¼ä 2020-12-220x00 Îó²î¸ÅÊö
²úÆ·Ãû³Æ | CVE ID | Àà ÐÍ | Îó²îÆ·¼¶ | Ô¶³ÌʹÓà |
Dell Wyse Thin Clients | CVE-2020-29491 | RCE | ÑÏÖØ | ÊÇ |
CVE-2020-29492 | RCE | ÑÏÖØ | ÊÇ |
0x01 Îó²îÏêÇé

Thin clientsÊÇÒ»ÖÖ¾ÓÉÓÅ»¯µÄСÐÍÅÌËã»ú£¬£¬£¬£¬£¬£¬Ö÷ÒªÓÃÓÚÔ¶³Ì×ÀÃæ£¬£¬£¬£¬£¬£¬ÒÔÅþÁ¬µ½ÆäËüϵͳ¡£¡£¡£¡£¡£¡£¡£¡£Wyse×Ô1990ÄêÒÔÀ´Ò»Ö±ÔÚ¿ª·¢Thin clients£¬£¬£¬£¬£¬£¬²¢ÓÚ2012Äê±»DellÊÕ¹º¡£¡£¡£¡£¡£¡£¡£¡£
2020Äê12ÔÂ21ÈÕ£¬£¬£¬£¬£¬£¬Dell¹Ù·½Ðû²¼Ç徲ͨ¸æ£¬£¬£¬£¬£¬£¬Dell Wyse ThinOSÖб£´æÁ½¸öÑÏÖØÎó²î£¨CVE-2020-29491ºÍCVE-2020-29492£©¡£¡£¡£¡£¡£¡£¡£¡£
ÏêÇéÈçÏ£º
ThinOS¿ÉÒÔÔ¶³Ìά»¤£¬£¬£¬£¬£¬£¬ÆäĬÈÏ·½·¨ÊÇͨ¹ýÍâµØFTPЧÀÍÆ÷ÏÂÔØÐµĹ̼þ¡¢Èí¼þ°üºÍÉèÖᣡ£¡£¡£¡£¡£¡£¡£
Dell½¨ÒéʹÓÃMicrosoft IIS½¨ÉèFTPЧÀÍÆ÷£¬£¬£¬£¬£¬£¬È»ºóÔÊÐí»á¼û¿Éͨ¹ýFTPЧÀÍÆ÷»á¼ûµÄ¹Ì¼þ¡¢Èí¼þ°üºÍINIÎļþ¡£¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚFTPÉèÖÃΪ²»ÐèҪƾ֤£¨¡°ÄäÃû¡±Óû§£©£¬£¬£¬£¬£¬£¬ÕâʹµÃFTPЧÀÍÆ÷ÉÏÌØ¶¨µÄINIÎļþ¿ÉÒÔ±»ÅþÁ¬µÄ¿Í»§¶ËдÈë¡£¡£¡£¡£¡£¡£¡£¡£ÔÚFTPЧÀÍÆ÷ÉÏÕÒµ½µÄ¹Ì¼þºÍ³ÌÐò°üÎļþÒÑÊðÃû£¬£¬£¬£¬£¬£¬µ«ÓÃÓÚÉèÖõÄINIÎļþδÊðÃû¡£¡£¡£¡£¡£¡£¡£¡£Òò´Ë£¬£¬£¬£¬£¬£¬ÍøÂçÉϵÄÈκι¥»÷Õß¶¼¿ÉÒÔ»á¼ûFTPЧÀÍÆ÷²¢ÐÞ¸ÄThin clientsµÄINIÉèÖÃÎļþ²¢ÉúÑÄ¡£¡£¡£¡£¡£¡£¡£¡£
±ðµÄ£¬£¬£¬£¬£¬£¬×ÝÈ»ÉèÖÃÁËÆ¾Ö¤£¬£¬£¬£¬£¬£¬ËüÃÇÒ²½«ÔÚ´ó×Ú¿Í»§¶ËÖ®¼ä¹²Ïí£¬£¬£¬£¬£¬£¬´Ó¶øÔÊÐíËüÃǸü¸ÄÏ໥µÄINIÉèÖÃÎļþ¡£¡£¡£¡£¡£¡£¡£¡£
µ±Dell Wyse×°±¸ÅþÁ¬µ½FTPЧÀÍÆ÷ʱ£¬£¬£¬£¬£¬£¬Ëü»áÒÔ¡°{username}.INI¡±µÄÐÎʽËÑË÷INIÎļþ£¬£¬£¬£¬£¬£¬ÆäÖÐ{username}½«Ì滻ΪÖÕ¶ËʹÓõÄÓû§Ãû¡£¡£¡£¡£¡£¡£¡£¡£
ÈôÊÇÕâ¸öINIÎļþ±£´æ£¬£¬£¬£¬£¬£¬×°±¸½«´ÓÖмÓÔØÉèÖᣡ£¡£¡£¡£¡£¡£¡£ÓÉÓÚ¸ÃÎļþ¿Éд£¬£¬£¬£¬£¬£¬Òò´Ë¹¥»÷Õß¿ÉÒÔÐÞ¸ÄËüÀ´ÐÞ¸ÄÓû§µÄÉèÖ㬣¬£¬£¬£¬£¬×îÖÕ¿ÉÒÔÔÚÄ¿µÄϵͳÉÏÔ¶³ÌÖ´ÐдúÂë¡£¡£¡£¡£¡£¡£¡£¡£
Dell Wyse ThinOS ĬÈÏÉèÖùýʧÎó²î£¨CVE-2020-29491£©
¸ÃÎó²îÊDz»Çå¾²µÄĬÈÏÉèÖÃÔì³ÉµÄ£¬£¬£¬£¬£¬£¬ÆäCVSSÆÀ·ÖΪ10.0·Ö¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔͨ¹ýʹÓôËÎó²îÀ´»á¼ûÄ¿µÄϵͳÉϵÄÃô¸ÐÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£¡£
Dell Wyse ThinOS ĬÈÏÉèÖùýʧÎó²î£¨CVE-2020-29492£©
¸ÃÎó²îÊDz»Çå¾²µÄĬÈÏÉèÖÃÔì³ÉµÄ£¬£¬£¬£¬£¬£¬ÆäCVSSÆÀ·ÖΪ10.0·Ö¡£¡£¡£¡£¡£¡£¡£¡£¹¥»÷Õß¿ÉÒÔͨ¹ýʹÓôËÎó²îÀ´»á¼û¿ÉдÎļþ²¢ÐÞ¸ÄÄ¿µÄϵͳÉϵÄThin clientsµÄÉèÖᣡ£¡£¡£¡£¡£¡£¡£
Ó°Ïì¹æÄ££º
Dell Wyse ThinOS 8.6 MR8֮ǰµÄ°æ±¾
×èÖ¹ÏÖÔÚ£¬£¬£¬£¬£¬£¬Í¨¹ýZoomeyeËÑË÷£¬£¬£¬£¬£¬£¬È«Çò»òÐíÓÐ400¶àÍò¸öDell Wyse Thin clients¡£¡£¡£¡£¡£¡£¡£¡£

0x02 ´¦Öóͷ£½¨Òé
ÏÖÔÚDellÒѾÐû²¼ÁËÏà¹ØÇå¾²¸üУ¬£¬£¬£¬£¬£¬½¨Òé²Î¿¼Ï±íʵʱÐÞ¸´¡£¡£¡£¡£¡£¡£¡£¡£
²úÆ· | ÊÜÓ°Ïì°æ±¾ | ÐÞ¸´°æ±¾ | Á´½Ó |
Dell Wyse 3040 Thin Client (ENG) | 8.6 MR8֮ǰµÄ°æ±¾ | 8.6 MR8 | https://www.dell.com/support/home/drivers/driversdetails?driverid=cxv3j&oscode=thn80&productcode=wyse-3040-thin-client |
Dell Wyse 3040 Thin Client (JPN) | 8.6 MR8֮ǰµÄ°æ±¾ | 8.6 MR8 | https://www.dell.com/support/home/drivers/driversdetails?driverid=vry7h&oscode=thn80&productcode=wyse-3040-thin-client |
Dell Wyse 3040 Thin Client with PCoIP (ENG) | 8.6 MR8֮ǰµÄ°æ±¾ | 8.6 MR8 | https://www.dell.com/support/home/drivers/driversdetails?driverid=5dx5y&oscode=thn8p&productcode=wyse-3040-thin-client |
Dell Wyse 3040 Thin Client with PCoIP (JPN) | 8.6 MR8֮ǰµÄ°æ±¾ | 8.6 MR8 | https://www.dell.com/support/home/drivers/driversdetails?driverid=tk93y&oscode=thn80&productcode=wyse-3040-thin-client |
Dell Wyse 5010 Thin Client (ENG) | 8.6 MR8֮ǰµÄ°æ±¾ | 8.6 MR8 | https://www.dell.com/support/home/drivers/driversdetails?driverid=0ynjw&oscode=thn80&productcode=wyse-5010tc-series |
Dell Wyse 5010 Thin Client (JPN) | 8.6 MR8֮ǰµÄ°æ±¾ | 8.6 MR8 | https://www.dell.com/support/home/drivers/driversdetails?driverid=1nkvx&oscode=thn80&productcode=wyse-5010tc-series |
Dell Wyse 5010 Thin Client with PCoIP (ENG) | 8.6 MR8֮ǰµÄ°æ±¾ | 8.6 MR8 | https://www.dell.com/support/home/drivers/driversdetails?driverid=kv85h&oscode=thn8p&productcode=wyse-5010tc-series |
Dell Wyse 5010 Thin Client with PCoIP (JPN) | 8.6 MR8֮ǰµÄ°æ±¾ | 8.6 MR8 | https://www.dell.com/support/home/drivers/driversdetails?driverid=r39r6&oscode=thn8p&productcode=wyse-5010tc-series |
Dell Wyse 5040 Thin Client (ENG) | 8.6 MR8֮ǰµÄ°æ±¾ | 8.6 MR8 | https://www.dell.com/support/home/en-in/drivers/driversdetails?driverid=0ynjw&oscode=thn80&productcode=wyse-5010tc-series |
Dell Wyse 5040 Thin Client (JPN) | 8.6 MR8֮ǰµÄ°æ±¾ | 8.6 MR8 | https://www.dell.com/support/home/drivers/driversdetails?driverid=1nkvx&oscode=thn80&productcode=wyse-5010tc-series |
Dell Wyse 5040 Thin Client with PCoIP (ENG) | 8.6 MR8֮ǰµÄ°æ±¾ | 8.6 MR8 | https://www.dell.com/support/home/drivers/driversdetails?driverid=kv85h&oscode=thn8p&productcode=wyse-5010tc-series |
Dell Wyse 5040 Thin Client with PCoIP (JPN) | 8.6 MR8֮ǰµÄ°æ±¾ | 8.6 MR8 | https://www.dell.com/support/home/drivers/driversdetails?driverid=r39r6&oscode=thn8p&productcode=wyse-5010tc-series |
Dell Wyse 5060 Thin Client (ENG) | 8.6 MR8֮ǰµÄ°æ±¾ | 8.6 MR8 | https://www.dell.com/support/home/drivers/driversdetails?driverid=rdr2t&oscode=thn80&productcode=wyse-5060-thin-client |
Dell Wyse 5060 Thin Client (JPN) | 8.6 MR8֮ǰµÄ°æ±¾ | 8.6 MR8 | https://www.dell.com/support/home/drivers/driversdetails?driverid=8998g&oscode=thn80&productcode=wyse-5060-thin-client |
Dell Wyse 5060 Thin Client with PCoIP (ENG) | 8.6 MR8֮ǰµÄ°æ±¾ | 8.6 MR8 | https://www.dell.com/support/home/drivers/driversdetails?driverid=8jxd2&oscode=thn8p&productcode=wyse-5060-thin-client |
Dell Wyse 5060 Thin Client with PCoIP (JPN) | 8.6 MR8֮ǰµÄ°æ±¾ | 8.6 MR8 | https://www.dell.com/support/home/drivers/driversdetails?driverid=gwy2y&oscode=thn8p&productcode=wyse-5060-thin-client |
Dell Wyse 5070 Thin Client (ENG) | 8.6 MR8֮ǰµÄ°æ±¾ | 8.6 MR8 | https://www.dell.com/support/home/drivers/driversdetails?driverid=02vmh&oscode=thn80&productcode=wyse-5070-thin-client |
Dell Wyse 5070 Thin Client (JPN) | 8.6 MR8֮ǰµÄ°æ±¾ | 8.6 MR8 | https://www.dell.com/support/home/drivers/driversdetails?driverid=j0dx4&oscode=thn80&productcode=wyse-5070-thin-client |
Dell Wyse 5070 Thin Client with PCoIP (ENG) | 8.6 MR8֮ǰµÄ°æ±¾ | 8.6 MR8 | https://www.dell.com/support/home/drivers/driversdetails?driverid=rj0yw&oscode=thn8p&productcode=wyse-5070-thin-client |
Dell Wyse 5070 Thin Client with PCoIP (JPN) | 8.6 MR8֮ǰµÄ°æ±¾ | 8.6 MR8 | https://www.dell.com/support/home/drivers/driversdetails?driverid=kj6mp&oscode=thn8p&productcode=wyse-5070-thin-client |
Dell Wyse 5470 AIO Thin Client (ENG) | 8.6 MR8֮ǰµÄ°æ±¾ | 8.6 MR8 | https://www.dell.com/support/home/drivers/driversdetails?driverid=x38ch&oscode=thn80&productcode=wyse-5470-aio |
Dell Wyse 5470 AIO Thin Client (JPN) | 8.6 MR8֮ǰµÄ°æ±¾ | 8.6 MR8 | https://www.dell.com/support/home/drivers/driversdetails?driverid=4nx45&oscode=thn80&productcode=wyse-5470-aio |
Dell Wyse 5470 AIO Thin Client with PCoIP (ENG) | 8.6 MR8֮ǰµÄ°æ±¾ | 8.6 MR8 | https://www.dell.com/support/home/drivers/driversdetails?driverid=fw8tm&oscode=thn8p&productcode=wyse-5470-aio |
Dell Wyse 5470 AIO Thin Client with PCoIP (JPN) | 8.6 MR8֮ǰµÄ°æ±¾ | 8.6 MR8 | https://www.dell.com/support/home/drivers/driversdetails?driverid=m65dv&oscode=thn8p&productcode=wyse-5470-aio |
Dell Wyse 5470 Thin Client (ENG) | 8.6 MR8֮ǰµÄ°æ±¾ | 8.6 MR8 | https://www.dell.com/support/home/drivers/driversdetails?driverid=c0ncw&oscode=thn80&productcode=wyse-5470-mobile-thin-client |
Dell Wyse 5470 Thin Client (JPN) | 8.6 MR8֮ǰµÄ°æ±¾ | 8.6 MR8 | https://www.dell.com/support/home/drivers/driversdetails?driverid=4hjk3&oscode=thn80&productcode=wyse-5470-mobile-thin-client |
Dell Wyse 5470 Thin Client with PCoIP (ENG) | 8.6 MR8֮ǰµÄ°æ±¾ | 8.6 MR8 | https://www.dell.com/support/home/drivers/driversdetails?driverid=y3m10&oscode=thn8p&productcode=wyse-5470-mobile-thin-client |
Dell Wyse 5470 Thin Client with PCoIP (JPN) | 8.6 MR8֮ǰµÄ°æ±¾ | 8.6 MR8 | https://www.dell.com/support/home/drivers/driversdetails?driverid=ffwk9&oscode=thn8p&productcode=wyse-5470-mobile-thin-client |
Dell Wyse 7010 Thin Client (ENG) | 8.6 MR8֮ǰµÄ°æ±¾ | 8.6 MR8 | https://www.dell.com/support/home/drivers/driversdetails?driverid=0ynjw&oscode=thn80&productcode=wyse-5010tc-series |
Dell Wyse 7010 thin client (JPN) | 8.6 MR8֮ǰµÄ°æ±¾ | 8.6 MR8 | https://www.dell.com/support/home/drivers/driversdetails?driverid=1nkvx&oscode=thn80&productcode=wyse-5010tc-series |
»º½â²½·¥£º
l ʹÓÃÇå¾²ÐÒé¡£¡£¡£¡£¡£¡£¡£¡£ÈçʹÓÃHTTPSÈ¡´úHTTP»òFTP£¬£¬£¬£¬£¬£¬²¢È·±£ÎļþЧÀÍÆ÷»á¼ûȨÏÞÉèÖÃΪֻ¶Á¡£¡£¡£¡£¡£¡£¡£¡£
l ʹÓÃWyse Management Suite¶ø²»ÊÇÎļþЧÀÍÆ÷À´¾ÙÐÐ×°±¸ÉèÖᣡ£¡£¡£¡£¡£¡£¡£Wyse Management SuiteÍ¨Ñ¶Ç¿ÖÆÖ´ÐÐHTTPSÐÒ飬£¬£¬£¬£¬£¬ËùÓÐÉèÖö¼´æ´¢ÔÚÇå¾²µÄЧÀÍÆ÷Êý¾Ý¿âÖУ¬£¬£¬£¬£¬£¬¶ø²»ÊÇ´æ´¢Ôڿɱ༵ÄÉèÖÃÎļþÖС£¡£¡£¡£¡£¡£¡£¡£
l ʹÓÃThinOS 9µÄDell Wyse Management Suite¡£¡£¡£¡£¡£¡£¡£¡£ThinOS 9¿Í»§¶Ë²»Ö§³ÖÎļþЧÀÍÆ÷ÉèÖ㬣¬£¬£¬£¬£¬Òò´Ë¸ÃÎó²îÎÞ·¨Ê¹Óᣡ£¡£¡£¡£¡£¡£¡£
0x03 ²Î¿¼Á´½Ó
https://www.dell.com/support/kbdoc/en-us/000180768/dsa-2020-281
https://www.bleepingcomputer.com/news/security/critical-bugs-in-dell-wyse-thinos-allow-thin-client-take-over/
https://www.cybermdx.com/vulnerability-research-disclosures/dell-wyse-thin-client-vulnerability
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-29492
0x04 ʱ¼äÏß
2020-12-21 DellÐû²¼Ç徲ͨ¸æ
2020-12-22 VSRCÐû²¼Ç徲ͨ¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/



¾©¹«Íø°²±¸11010802024551ºÅ