Title: eSeSIX Thintune Thin Client Devices Multiple Vulnerabilities
Severity: CRITICAL
Description:
eSeSIX Thintune are thin client devices for server based computing.
Thintune Linux-based devices are reported prone to multiple vulnerabilities. These issues can allow remote attackers to gain complete access to a vulnerable device.
Thintune devices are prone to a backdoor account vulnerability. It is reported that an unspecified process runs on TCP port 25072. A remote attacker can gain access to a device by connecting to TCP port 25072 and supplying 'jstwo' as a password. This password is hard coded in the '/usr/bin/radmin' file and cannot be changed. Successful exploitation can allow an attacker to gain complete access to the device, issue various commands and carry out other attacks.
Another backdoor account can allow users of the thin client to gain unauthorized access to a vulnerable device. An attacker can exploit this issue by pressing <CTRL><SHIFT><ALT><DEL> and entering 'maertsJ' as a password. This password is hard coded in the '/usr/bin/lshell' file and cannot be changed.
It is reported that Thintune supports Web access for users through the Mozilla Firefox browser. An access validation issue can allow an attacker to browse the file system by accessing the devices through the Web browser. To exploit this issue, the attacker simply uses the 'file:///' URI to access the super user directory of the file system. It is reported that passwords for administrators and users are stored in various clear text files. This issue can allow an attacker to gain access to the sensitive information and therefore gain unauthorized access to devices and potentially compromise other computers on the network.
Thintune devices with firmware version 2.4.38 and prior are affected by these issues. Reportedly, Thintune devices based on Windows CE are not affected.
Affected Products:
- eSeSIX Thintune L 2.4.38 Firmware
- eSeSIX Thintune M 2.4.38 Firmware
- eSeSIX Thintune Mobile 2.4.38 Firmware
- eSeSIX Thintune S 2.4.38 Firmware
- eSeSIX Thintune XM 2.4.38 Firmware
- eSeSIX Thintune XS 2.4.38 Firmware
- eSeSIX Thintune eXtreme 2.4.38 Firmware
References:
- eSeSIX: Thintune Product Page
Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.