« Volver al listado

CVE-2009-0693

Estado: ModificadaAlta (7.5)—

Multiple buffer overflows in Wyse Device Manager (WDM) 4.7.x allow remote attackers to execute arbitrary code via (1) the User-Agent HTTP header to hserver.dll or (2) unspecified input to hagent.exe.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2009-0693",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cret@cert.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2012-06-19T20:55:02.037",
  "references": [
    {
      "url": "http://archives.neohapsis.com/archives/fulldisclosure/2009-07/0101.html",
      "source": "cret@cert.org"
    },
    {
      "url": "http://www.kb.cert.org/vuls/id/654545",
      "tags": [
        "US Government Resource"
      ],
      "source": "cret@cert.org"
    },
    {
      "url": "http://www.theregister.co.uk/2009/07/10/wyse_remote_exploit_bugs/",
      "source": "cret@cert.org"
    },
    {
      "url": "http://www.wyse.com/serviceandsupport/Wyse%20Security%20Bulletin%20WSB09-01.pdf",
      "source": "cret@cert.org"
    },
    {
      "url": "http://archives.neohapsis.com/archives/fulldisclosure/2009-07/0101.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.kb.cert.org/vuls/id/654545",
      "tags": [
        "US Government Resource"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.theregister.co.uk/2009/07/10/wyse_remote_exploit_bugs/",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.wyse.com/serviceandsupport/Wyse%20Security%20Bulletin%20WSB09-01.pdf",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-119"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Multiple buffer overflows in Wyse Device Manager (WDM) 4.7.x allow remote attackers to execute arbitrary code via (1) the User-Agent HTTP header to hserver.dll or (2) unspecified input to hagent.exe."
    },
    {
      "lang": "es",
      "value": "Múltiples desbordamientos de búfer en Wyse Device Manager (WDM) v4.7.x permite a atacantes remotos ejecutar código arbitrario a través de (1) el encabezado User-Agent HTTP para hserver.dll o (2) una entrada no especificada a hagent.exe."
    }
  ],
  "lastModified": "2026-06-16T23:05:35.137",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:dell:wyse_device_manager:4.7.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BCFCC250-4914-4ABD-B818-F09C26FCD884"
            },
            {
              "criteria": "cpe:2.3:a:dell:wyse_device_manager:4.7.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9B57C791-1D5C-40F7-B4B7-A8F85D45C327"
            },
            {
              "criteria": "cpe:2.3:a:dell:wyse_device_manager:4.7.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2D02CBA7-5B8C-40D2-8439-6FD51B7E86B9"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cret@cert.org"
}