ID

VAR-201902-0504


CVE

CVE-2018-15781


TITLE

ThinLinux2 Vulnerabilities related to the use of hard-coded credentials

Trust: 0.8

sources: JVNDB: JVNDB-2018-014509

DESCRIPTION

The Dell Wyse Password Encoder in ThinLinux2 versions prior to 2.1.0.01 contain a Hard-coded Cryptographic Key vulnerability. An unauthenticated remote attacker could reverse engineer the cryptographic system used in the Dell Wyse Password Encoder to discover the hard coded private key and decrypt locally stored cipher text. ThinLinux2 Contains a vulnerability in the use of hard-coded credentials.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. An attacker can exploit this issue to gain unauthorized access to the vulnerable device and perform unauthorized actions. Dell ThinLinux2 versions prior to 2.1.0.01 are vulnerable

Trust: 1.98

sources: NVD: CVE-2018-15781 // JVNDB: JVNDB-2018-014509 // BID: 107167 // VULHUB: VHN-126075

AFFECTED PRODUCTS

vendor:dellmodel:wyse thinlinuxscope:ltversion:2.1.0.01

Trust: 1.8

vendor:dellmodel:wyse thinlinuxscope:gteversion:2.0

Trust: 1.0

vendor:dellmodel:wyse thinlinuxscope:eqversion:2.0

Trust: 0.3

vendor:dellmodel:wyse thinlinuxscope:neversion:2.10.1

Trust: 0.3

sources: BID: 107167 // JVNDB: JVNDB-2018-014509 // NVD: CVE-2018-15781

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2018-15781
value: HIGH

Trust: 1.0

security_alert@emc.com: CVE-2018-15781
value: HIGH

Trust: 1.0

NVD: CVE-2018-15781
value: HIGH

Trust: 0.8

CNNVD: CNNVD-201902-549
value: HIGH

Trust: 0.6

VULHUB: VHN-126075
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2018-15781
severity: HIGH
baseScore: 7.9
vectorString: AV:A/AC:M/AU:N/C:C/I:C/A:C
accessVector: ADJACENT_NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 5.5
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-126075
severity: HIGH
baseScore: 7.9
vectorString: AV:A/AC:M/AU:N/C:C/I:C/A:C
accessVector: ADJACENT_NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 5.5
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2018-15781
baseSeverity: HIGH
baseScore: 8.0
vectorString: CVSS:3.0/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
attackVector: ADJACENT
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: REQUIRED
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 2.1
impactScore: 5.9
version: 3.0

Trust: 1.8

security_alert@emc.com: CVE-2018-15781
baseSeverity: HIGH
baseScore: 7.9
vectorString: CVSS:3.0/AV:A/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
attackVector: ADJACENT
attackComplexity: HIGH
privilegesRequired: NONE
userInteraction: REQUIRED
scope: CHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 1.2
impactScore: 6.0
version: 3.0

Trust: 1.0

sources: VULHUB: VHN-126075 // JVNDB: JVNDB-2018-014509 // CNNVD: CNNVD-201902-549 // NVD: CVE-2018-15781 // NVD: CVE-2018-15781

PROBLEMTYPE DATA

problemtype:CWE-798

Trust: 1.9

sources: VULHUB: VHN-126075 // JVNDB: JVNDB-2018-014509 // NVD: CVE-2018-15781

THREAT TYPE

remote or local

Trust: 0.6

sources: CNNVD: CNNVD-201902-549

TYPE

trust management problem

Trust: 0.6

sources: CNNVD: CNNVD-201902-549

CONFIGURATIONS

sources: JVNDB: JVNDB-2018-014509

PATCH

title:DSA-2019-022url:https://www.dell.com/support/article/jp/ja/jpdhs1/sln316104/dsa-2019-022-dell-wyse-password-encoderハードコード暗号キーの脆弱性?lang=ja

Trust: 0.8

title:ThinLinux2 Security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=89353

Trust: 0.6

sources: JVNDB: JVNDB-2018-014509 // CNNVD: CNNVD-201902-549

EXTERNAL IDS

db:NVDid:CVE-2018-15781

Trust: 2.8

db:JVNDBid:JVNDB-2018-014509

Trust: 0.8

db:CNNVDid:CNNVD-201902-549

Trust: 0.7

db:BIDid:107167

Trust: 0.3

db:VULHUBid:VHN-126075

Trust: 0.1

sources: VULHUB: VHN-126075 // BID: 107167 // JVNDB: JVNDB-2018-014509 // CNNVD: CNNVD-201902-549 // NVD: CVE-2018-15781

REFERENCES

url:https://www.dell.com/support/article/sln316104

Trust: 1.7

url:https://nvd.nist.gov/vuln/detail/cve-2018-15781

Trust: 1.4

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2018-15781

Trust: 0.8

url:http://dell.com

Trust: 0.3

url:https://www.dell.com/support/article/us/en/19/sln316104/dsa-2019-022-dell-wyse-password-encoder-hard-coded-cryptographic-key-vulnerability?lang=en

Trust: 0.3

sources: VULHUB: VHN-126075 // BID: 107167 // JVNDB: JVNDB-2018-014509 // CNNVD: CNNVD-201902-549 // NVD: CVE-2018-15781

CREDITS

Andrew Tierney at Pen Test Partners

Trust: 0.3

sources: BID: 107167

SOURCES

db:VULHUBid:VHN-126075
db:BIDid:107167
db:JVNDBid:JVNDB-2018-014509
db:CNNVDid:CNNVD-201902-549
db:NVDid:CVE-2018-15781

LAST UPDATE DATE

2024-11-23T22:26:03.797000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-126075date:2019-10-09T00:00:00
db:BIDid:107167date:2019-02-06T00:00:00
db:JVNDBid:JVNDB-2018-014509date:2019-03-25T00:00:00
db:CNNVDid:CNNVD-201902-549date:2019-10-17T00:00:00
db:NVDid:CVE-2018-15781date:2024-11-21T03:51:27.333

SOURCES RELEASE DATE

db:VULHUBid:VHN-126075date:2019-02-13T00:00:00
db:BIDid:107167date:2019-02-06T00:00:00
db:JVNDBid:JVNDB-2018-014509date:2019-03-25T00:00:00
db:CNNVDid:CNNVD-201902-549date:2019-02-13T00:00:00
db:NVDid:CVE-2018-15781date:2019-02-13T16:29:00.297