Wyse Management Subversion: Taking over Dell’s Wyse Management Suite
By its own definition, Dell’s Wyse Management Suite is „a secure hybrid cloud management solution for Dell thin clients”. While attempting to determine how secrets are encrypted in the policies pushed to thin clients, we stumbled down a rabbit hole which led to the discovery of multiple vulnerabilities.
These vulnerabilities allow not only to decrypt the secrets from policies issued to arbitrary devices, but also to fully compromise the Wyse Management Suite server, which in turn allows to take over all the devices in the thin client fleet.
While these issues are already important in the case of on-premise deployments, the risk is even higher in Dell’s own cloud environment, where tenant isolation is not sufficient to prevent exploitation from one tenant to another.
About the speaker

Alain Mowat
Read more …