CVE-2022-33925Improper Access Control in Dell Wyse Management Suite

Severity
6.5MEDIUMNVD
EPSS
0.2%
top 62.74%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 10
Latest updateAug 11

Description

Dell Wyse Management Suite 3.6.1 and below contains an Improper Access control vulnerability in UI. An remote authenticated attacker could potentially exploit this vulnerability by bypassing access controls in order to download reports containing sensitive information.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages2 packages

CVEListV5dell/wyse_management_suiteunspecified3.7

🔴Vulnerability Details

2
GHSA
GHSA-4jr4-78x2-94mm: Dell Wyse Management Suite 32022-08-11
CVEList
CVE-2022-33925: Dell Wyse Management Suite 32022-08-10
CVE-2022-33925 — Improper Access Control in Dell | cvebase