cbcvebase.

Dell Wyse Management Suite vulnerabilities

70 known vulnerabilities affecting dell/wyse_management_suite.

Total CVEs
70
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL6HIGH21MEDIUM40LOW3

Vulnerabilities

Page 1 of 4
CVE-2021-21586P3MEDIUMCVSS 6.5PoC≤ 3.2≥ unspecified, < 3.32021-07-15
CVE-2021-21586 [MEDIUM] CWE-36 CVE-2021-21586: Wyse Management Suite versions 3.2 and earlier contain an absolute path traversal vulnerability. A r Wyse Management Suite versions 3.2 and earlier contain an absolute path traversal vulnerability. A remote authenticated malicious user could exploit this vulnerability in order to read arbitrary files on the system.
nvd
CVE-2026-81236P2CRITICALCVSS 9.8fixed in 2605.0.3.683fixed in WMS 2605.0.3.6832026-09-15
CVE-2026-81236 [CRITICAL] CWE-434 CVE-2026-81236: Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Unrestricted Upload of File w Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Unrestricted Upload of File with Dangerous Type vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.
nvd
CVE-2026-81239P2CRITICALCVSS 9.8fixed in 2605.0.3.683fixed in WMS 2605.0.3.6832026-09-15
CVE-2026-81239 [CRITICAL] CWE-434 CVE-2026-81239: Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Unrestricted Upload of File w Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Unrestricted Upload of File with Dangerous Type vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.
nvd
CVE-2026-81240P2CRITICALCVSS 9.8fixed in 2605.0.3.683fixed in WMS 2605.0.3.6832026-09-15
CVE-2026-81240 [CRITICAL] CWE-434 CVE-2026-81240: Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Unrestricted Upload of File w Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Unrestricted Upload of File with Dangerous Type vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.
nvd
CVE-2026-41120P2CRITICALCVSS 9.8fixed in 5.5v5.5+1 more2026-06-25
CVE-2026-41120 [CRITICAL] CWE-349 CVE-2026-41120: Dell Wyse Management Suite, versions prior to WMS 5.5 HF1, contain an Acceptance of Extraneous Untru Dell Wyse Management Suite, versions prior to WMS 5.5 HF1, contain an Acceptance of Extraneous Untrusted Data With Trusted Data vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote Code Execution.
nvd
CVE-2026-81238P2CRITICALCVSS 9.1fixed in 2605.0.3.683fixed in WMS 2605.0.3.6832026-09-15
CVE-2026-81238 [CRITICAL] CWE-306 CVE-2026-81238: Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain a Missing Authentication for Cri Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.
nvd
CVE-2026-44272P2HIGHCVSS 8.8fixed in 26052026-06-22
CVE-2026-44272 [HIGH] CWE-89 CVE-2026-44272: Dell Wyse Management Suite (WMS), versions prior to WMS 2605, contain an Improper Neutralization of Dell Wyse Management Suite (WMS), versions prior to WMS 2605, contain an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.
nvd
CVE-2026-44271P2HIGHCVSS 8.8fixed in 26052026-06-22
CVE-2026-44271 [HIGH] CWE-89 CVE-2026-44271: Dell Wyse Management Suite (WMS), versions prior to WMS 2605, contain an Improper Neutralization of Dell Wyse Management Suite (WMS), versions prior to WMS 2605, contain an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.
nvd
CVE-2021-36336P2CRITICALCVSS 9.8≤ 3.3.1≥ unspecified, < 3.52021-12-21
CVE-2021-36336 [CRITICAL] CWE-502 CVE-2021-36336: Wyse Management Suite 3.3.1 and below versions contain a deserialization vulnerability that could al Wyse Management Suite 3.3.1 and below versions contain a deserialization vulnerability that could allow an unauthenticated attacker to execute code on the affected system.
nvd
CVE-2026-22765P3HIGHCVSS 8.8fixed in 5.5fixed in 5.5*2026-02-24
CVE-2026-22765 [HIGH] CWE-862 CVE-2026-22765: Dell Wyse Management Suite, versions prior to WMS 5.5, contain a Missing Authorization vulnerability Dell Wyse Management Suite, versions prior to WMS 5.5, contain a Missing Authorization vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of Privileges.
nvd
CVE-2022-33928P3HIGHCVSS 8.8fixed in 3.8.0≥ unspecified, < 3.72022-08-10
CVE-2022-33928 [HIGH] CWE-256 CVE-2022-33928: Dell Wyse Management Suite 3.6.1 and below contains an Plain-text Password Storage Vulnerability in Dell Wyse Management Suite 3.6.1 and below contains an Plain-text Password Storage Vulnerability in UI. An attacker with low privileges could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials to access the vulnerable application with privileges of the c
nvd
CVE-2026-49506P3HIGHCVSS 7.2fixed in 5.5v5.5+1 more2026-06-25
CVE-2026-49506 [HIGH] CWE-22 CVE-2026-49506: Dell Wyse Management Suite, versions prior to WMS 5.5 HF1, contain an Improper Limitation of a Pathn Dell Wyse Management Suite, versions prior to WMS 5.5 HF1, contain an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote Code Execution.
nvd
CVE-2025-36574P3HIGHCVSS 8.2fixed in 5.2≥ N/A, < 5.22025-06-10
CVE-2025-36574 [HIGH] CWE-36 CVE-2025-36574: Dell Wyse Management Suite, versions prior to WMS 5.2, contain an Absolute Path Traversal vulnerabil Dell Wyse Management Suite, versions prior to WMS 5.2, contain an Absolute Path Traversal vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure and Unauthorized access.
nvd
CVE-2026-66271P3HIGHCVSS 7.2fixed in 2605.0.22026-08-14
CVE-2026-66271 [HIGH] CWE-434 CVE-2026-66271: Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Unrestricted Upload of File Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Unrestricted Upload of File with Dangerous Type vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote Code Execution.
nvd
CVE-2026-66270P3HIGHCVSS 7.2fixed in 2605.0.22026-08-14
CVE-2026-66270 [HIGH] CWE-434 CVE-2026-66270: Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Unrestricted Upload of File Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Unrestricted Upload of File with Dangerous Type vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote Code Execution.
nvd
CVE-2026-22766P3HIGHCVSS 7.2fixed in 5.5fixed in 5.5*2026-02-24
CVE-2026-22766 [HIGH] CWE-434 CVE-2026-22766: Dell Wyse Management Suite, versions prior to WMS 5.5, contain an Unrestricted Upload of File with D Dell Wyse Management Suite, versions prior to WMS 5.5, contain an Unrestricted Upload of File with Dangerous Type vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.
nvd
CVE-2025-36575P3HIGHCVSS 7.5fixed in 5.2≥ N/A, < 5.22025-06-10
CVE-2025-36575 [HIGH] CWE-202 CVE-2025-36575: Dell Wyse Management Suite, versions prior to WMS 5.2, contain an Exposure of Sensitive Information Dell Wyse Management Suite, versions prior to WMS 5.2, contain an Exposure of Sensitive Information Through Data Queries vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.
nvd
CVE-2024-49597P3HIGHCVSS 7.2≤ 4.4≥ N/A, ≤ 4.42024-11-26
CVE-2024-49597 [HIGH] CWE-307 CVE-2024-49597: Dell Wyse Management Suite, versions WMS 4.4 and prior, contain an Improper Restriction of Excessive Dell Wyse Management Suite, versions WMS 4.4 and prior, contain an Improper Restriction of Excessive Authentication Attempts vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Protection mechanism bypass.
nvd
CVE-2026-63700P3HIGHCVSS 7.8fixed in 2605.0.22026-08-14
CVE-2026-63700 [HIGH] CWE-269 CVE-2026-63700: Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Incorrect Default Permissio Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Incorrect Default Permission vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Privilege Escalation.
nvd
CVE-2025-29981P3HIGHCVSS 7.5fixed in 5.1≥ N/A, < 5.12025-04-02
CVE-2025-29981 [HIGH] CWE-202 CVE-2025-29981: Dell Wyse Management Suite, versions prior to WMS 5.1, contains an Exposure of Sensitive Information Dell Wyse Management Suite, versions prior to WMS 5.1, contains an Exposure of Sensitive Information Through Data Queries vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.
nvd
Dell Wyse Management Suite vulnerabilities | cvebase