21 December 20, 20:11
Quote:Dell has patched two critical security vulnerabilities in its Dell Wyse Thin Client Devices, which are small form-factor computers optimized for connecting to a remote desktop. The bugs allow arbitrary code execution and the ability to access files and credentials, researchers said.
Thin clients contain none of the typical processing power or intelligence on board that normal PCs would have; instead, they act as less-smart terminals that connect to applications hosted on a remote computer. They’re often used in environments where employers give workers access to only a certain set of applications or resources; or for remote workers to connect back to headquarters.
Wyse has been developing thin clients since the 1990s and was acquired by Dell in 2012. In the U.S. alone, more than 6,000 companies and organizations are using Dell Wyse thin clients inside their network, with many of these (but not all) being healthcare providers, according to researchers at CyberMDX, who discovered the flaws.
Read more: https://threatpost.com/critical-bugs-del...ts/162452/