CVE-2009-0695 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 68.9% (pctl 99)
Patch early
A public exploit exists.
Description
hagent.exe in Wyse Device Manager (WDM) 4.7.x does not require authentication for commands, which allows remote attackers to obtain management access via a crafted query, as demonstrated by a V52 query that triggers a power-off action.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 68.89% — more likely to be exploited than 99% of all CVEs |
| Weakness | CWE-287 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2012-06-19 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| dell | wyse device manager |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Wyse - Machine Remote Power Off (Denial of Service) (Metasploit) | 2012-06-14 |
| exploit-db | Wyse Rapport Hagent Fake Hserver - Command Execution (Metasploit) | 2009-07-10 |
References
- http://archives.neohapsis.com/archives/fulldisclosure/2009-07/0101.html
- http://www.exploit-db.com/exploits/19137/
- http://www.kb.cert.org/vuls/id/654545
- http://www.theregister.co.uk/2009/07/10/wyse_remote_exploit_bugs/
- http://www.wyse.com/serviceandsupport/Wyse%20Security%20Bulletin%20WSB09-01.pdf
- http://archives.neohapsis.com/archives/fulldisclosure/2009-07/0101.html
- http://www.exploit-db.com/exploits/19137/
- http://www.kb.cert.org/vuls/id/654545
- http://www.theregister.co.uk/2009/07/10/wyse_remote_exploit_bugs/
- http://www.wyse.com/serviceandsupport/Wyse%20Security%20Bulletin%20WSB09-01.pdf
→ the Explorer · watch your stack · NVD