Back

HIGH

DSA-2019-022: Dell Wyse Password Encoder Hard-coded Cryptographic Key Vulnerability

Published Feb 13, 2019

Description

The Dell Wyse Password Encoder in ThinLinux2 versions prior to 2.1.0.01 contain a Hard-coded Cryptographic Key vulnerability. An unauthenticated remote attacker could reverse engineer the cryptographic system used in the Dell Wyse Password Encoder to discover the hard coded private key and decrypt locally stored cipher text.

Affected products

Remediation

Vendor solution

The following Dell ThinLinux2 release contains a resolution to the vulnerability:

Dell ThinLinux2 versions 2.1.0.01 and later Dell recommends all customers upgrade at the earliest opportunity. For more information, refer to Dell Knowledge Base article Drivers and Downloads FAQs.

Link to remedies:

Customers can download software from

https://www.dell.com/support/home/us/en/19/drivers/driversdetails?driverId=C4JH3&osCode=THNLX&productCode=wyse-3040-thin-client

https://www.dell.com/support/home/in/en/indhs1/drivers/driversdetails?driverId=3CKT3&osCode=THNLX&productCode=wyse-5070-thin-client

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner dell
Published Feb 13, 2019
Updated Sep 16, 2024
Reserved Aug 23, 2018
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a