VYPR

Wyse Device Manager

Sign in to watch

by Dell

CVEs (2)

CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2009-06950.080.64Jun 19, 2012hagent.exe in Wyse Device Manager (WDM) 4.7.x does not require authentication for commands, which allows remote attackers to obtain management access via a crafted query, as demonstrated by a V52 query that triggers a power-off action.
CVE-2009-06930.040.16Jun 19, 2012Multiple buffer overflows in Wyse Device Manager (WDM) 4.7.x allow remote attackers to execute arbitrary code via (1) the User-Agent HTTP header to hserver.dll or (2) unspecified input to hagent.exe.