CVE-2009-0695

Wyse Device Manager <4.7.x - RCE

Title source: llm

Description

hagent.exe in Wyse Device Manager (WDM) 4.7.x does not require authentication for commands, which allows remote attackers to obtain management access via a crafted query, as demonstrated by a V52 query that triggers a power-off action.

Exploits (3)

exploitdb WORKING POC
by it.solunium · rubydoshardware
https://www.exploit-db.com/exploits/19137
exploitdb WORKING POC VERIFIED
by kf · rubyremotemultiple
https://www.exploit-db.com/exploits/9934
metasploit WORKING POC EXCELLENT
rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/wyse/hagent_untrusted_hsdata.rb

Scores

EPSS 0.6423
EPSS Percentile 98.4%

Classification

CWE
CWE-287
Status draft

Affected Products (3)

dell/wyse_device_manager
dell/wyse_device_manager
dell/wyse_device_manager

Timeline

Published Jun 19, 2012
Tracked Since Feb 18, 2026