BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//pretalx.com//hack-lu-2025//talk//EB7SPU
BEGIN:VTIMEZONE
TZID:CET
BEGIN:STANDARD
DTSTART:20001029T040000
RRULE:FREQ=YEARLY;BYDAY=-1SU;BYMONTH=10
TZNAME:CET
TZOFFSETFROM:+0200
TZOFFSETTO:+0100
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20000326T030000
RRULE:FREQ=YEARLY;BYDAY=-1SU;BYMONTH=3
TZNAME:CEST
TZOFFSETFROM:+0100
TZOFFSETTO:+0200
END:DAYLIGHT
END:VTIMEZONE
BEGIN:VEVENT
UID:pretalx-hack-lu-2025-EB7SPU@pretalx.com
DTSTART;TZID=CET:20251023T163000
DTEND;TZID=CET:20251023T170000
DESCRIPTION:By it's own definition\, Dell's Wyse Management Suite is "a sec
 ure hybrid cloud management solution for Dell thin clients". While attempt
 ing to determine how secrets are encrypted in the policies pushed to thin 
 clients\, we stumbled down a rabbit hole which led to the discovery of mul
 tiple vulnerabilities. \n\nThese vulnerabilities allow not only to decrypt
  the secrets from policies issued to arbitrary devices\, but also to fully
  compromise the Wyse Management Suite server\, which in turn allows to tak
 e over all the devices in the thin client fleet. \n\nWhile these issues ar
 e already important in the case of on-premise deployments\, the risk is ev
 en higher in Dell's own cloud environment\, where tenant isolation is not 
 sufficient to prevent exploitation from one tenant to another.
DTSTAMP:20260711T203211Z
LOCATION:Europe
SUMMARY:Wyse Management Subversion : Taking over Dell's Wyse Management Sui
 te - Alain Mowat
URL:https://pretalx.com/hack-lu-2025/talk/EB7SPU/
END:VEVENT
END:VCALENDAR
