CVE-2021-21587
published 2021-07-15CVE-2021-21587: Dell Wyse Management Suite versions 3.2 and earlier contain a full path disclosure vulnerability. A local unauthenticated attacker could exploit this…
PriorityP417low3.3CVSS 3.1
AVLACLPRLUINSUCLINAN
EXPLOIT
EPSS
0.93%
56.3th percentile
Dell Wyse Management Suite versions 3.2 and earlier contain a full path disclosure vulnerability. A local unauthenticated attacker could exploit this vulnerability in order to obtain the path of files and folders.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| dell | wyse_management_suite | <= 3.2 | — |
| dell | wyse_management_suite | >= unspecified < 3.3 | 3.3 |
CVSS provenance
nvdv3.13.3LOWCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
Nuclei
Dell Wyse Management Suite Login Panel - Detect
nuclei
CVE-2021-21586 Dell Wyse Management Suite Login Panel - Detect
Dell Wyse Management Suite Login Panel - Detect
Dell Wyse Management Suite login panel was detected.
Template:
id: dell-wyse-login
info:
name: Dell Wyse Management Suite Login Panel - Detect
author: gy741
severity: info
description: Dell Wyse Management Suite login panel was detected.
reference:
- https://research.nccgroup.com/2021/07/06/technical-advisory-arbitrary-file-read-in-dell-wyse-management-suite-cve-2021-21586-cve-2021-21587/
classification:
cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N
cwe-id: CWE-200
cpe: cpe:2.3:a:dell:wyse_management_suite:*:*:*:*:*:*:*:*
metadata:
max-request: 1
vendor: dell
product: wyse_management_suite
tags: panel,dell,login,discovery
http:
- method: GET
path:
- '{{BaseURL}}/ccm-web/'
matchers-condition: and
matchers:
- type: word
words
No writeups or analysis indexed.
2021-07-15
Published