CVE-2022-46677Improper Access Control in Dell Wyse Management Suite

Severity
4.9MEDIUMNVD
CNA6.8
EPSS
0.3%
top 49.19%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 11

Description

Wyse Management Suite 3.8 and below contain an improper access control vulnerability with which an custom group admin can create a subgroup under a group for which the admin is not authorized.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:HExploitability: 1.2 | Impact: 3.6

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-qr2c-6mgv-f58v: Wyse Management Suite 32023-02-11
CVEList
CVE-2022-46677: Wyse Management Suite 32023-02-10
CVE-2022-46677 — Improper Access Control in Dell | cvebase