SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information

Report a Vulnerability

 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

Vulnerability Note VU#278785

DevonIT weak authentication and buffer overflow in /usr/bin/tm-console-bin

Overview

The DevonIT management tool for thin clients uses a shared secret that is transmitted over the network in the clear. The /usr/bin/tm-console-bin application contains a buffer overflow, which may allow an attacker to execute arbitrary code.

I. Description

The management tool transmits an unencrypted shared secret over the network to authenticate with clients. This traffic can then be used by an attacker to mimic a thin-manager server and control thin clients.

II. Impact

An attacker able to sniff traffic created by the management tool will be able to compromise the configuration of thin clients. An attacker may be able to exploit a buffer overflow in /usr/bin/tm-console-bin to execute arbitrary code.

III. Solution

We are currently unaware of a practical solution to this problem.

Restrict Access
Implement appropriate firewall rules so clients will only talk to a legitimate management server.

Vendor Information

VendorStatusDate NotifiedDate Updated
Devon IT Inc.Affected2009-09-172010-08-10

References

Credit

Thanks to Kevin Finisterre for reporting this vulnerability.

This document was written by Jared Allar.

Other Information

Date Public:2010-08-24
Date First Published:2010-08-24
Date Last Updated:2010-08-24
CERT Advisory: 
CVE-ID(s): 
NVD-ID(s): 
US-CERT Technical Alerts: 
Severity Metric:0.03
Document Revision:14

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Produced 2010 by US-CERT, a government organization
Disclaimers and copyright information
Get a PDF Reader