CVE-2018-15781
Summary
| CVE | CVE-2018-15781 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-02-13 16:29:00 UTC |
| Updated | 2019-10-09 23:35:00 UTC |
| Description | The Dell Wyse Password Encoder in ThinLinux2 versions prior to 2.1.0.01 contain a Hard-coded Cryptographic Key vulnerability. An unauthenticated remote attacker could reverse engineer the cryptographic system used in the Dell Wyse Password Encoder to discover the hard coded private key and decrypt locally stored cipher text. |
Risk And Classification
Problem Types: CWE-798
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Dell | Wyse Thinlinux | All | All | All | All |
| Application | Dell | Wyse Thinlinux | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| DSA-2019-022: Dell Wyse Password Encoder Hard-coded Cryptographic Key Vulnerability | Dell US | MISC | www.dell.com | Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Dell would like to thank Andrew Tierney at Pen Test Partners for reporting this vulnerability.
There are currently no legacy QID mappings associated with this CVE.