cbcvebase.

Dell Wyse Management Suite vulnerabilities

58 known vulnerabilities affecting dell/wyse_management_suite.

Total CVEs
58
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH17MEDIUM36LOW3

Vulnerabilities

Page 1 of 3
CVE-2026-41120P2CRITICALCVSS 9.8fixed in 5.5v5.5+1 more2026-06-25
CVE-2026-41120 [CRITICAL] CWE-349 CVE-2026-41120: Dell Wyse Management Suite, versions prior to WMS 5.5 HF1, contain an Acceptance of Extraneous Untru Dell Wyse Management Suite, versions prior to WMS 5.5 HF1, contain an Acceptance of Extraneous Untrusted Data With Trusted Data vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote Code Execution.
nvd
CVE-2021-21586P3MEDIUMCVSS 6.5PoC≤ 3.2≥ unspecified, < 3.32021-07-15
CVE-2021-21586 [MEDIUM] CWE-36 CVE-2021-21586: Wyse Management Suite versions 3.2 and earlier contain an absolute path traversal vulnerability. A r Wyse Management Suite versions 3.2 and earlier contain an absolute path traversal vulnerability. A remote authenticated malicious user could exploit this vulnerability in order to read arbitrary files on the system.
nvd
CVE-2021-36336P2CRITICALCVSS 9.8≤ 3.3.1≥ unspecified, < 3.52021-12-21
CVE-2021-36336 [CRITICAL] CWE-502 CVE-2021-36336: Wyse Management Suite 3.3.1 and below versions contain a deserialization vulnerability that could al Wyse Management Suite 3.3.1 and below versions contain a deserialization vulnerability that could allow an unauthenticated attacker to execute code on the affected system.
nvd
CVE-2026-44272P2HIGHCVSS 8.8fixed in 26052026-06-22
CVE-2026-44272 [HIGH] CWE-89 CVE-2026-44272: Dell Wyse Management Suite (WMS), versions prior to WMS 2605, contain an Improper Neutralization of Dell Wyse Management Suite (WMS), versions prior to WMS 2605, contain an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.
nvd
CVE-2026-44271P2HIGHCVSS 8.8fixed in 26052026-06-22
CVE-2026-44271 [HIGH] CWE-89 CVE-2026-44271: Dell Wyse Management Suite (WMS), versions prior to WMS 2605, contain an Improper Neutralization of Dell Wyse Management Suite (WMS), versions prior to WMS 2605, contain an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.
nvd
CVE-2026-22765P3HIGHCVSS 8.8fixed in 5.5fixed in 5.5*2026-02-24
CVE-2026-22765 [HIGH] CWE-862 CVE-2026-22765: Dell Wyse Management Suite, versions prior to WMS 5.5, contain a Missing Authorization vulnerability Dell Wyse Management Suite, versions prior to WMS 5.5, contain a Missing Authorization vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of Privileges.
nvd
CVE-2022-33928P3HIGHCVSS 8.8fixed in 3.8.0≥ unspecified, < 3.72022-08-10
CVE-2022-33928 [HIGH] CWE-256 CVE-2022-33928: Dell Wyse Management Suite 3.6.1 and below contains an Plain-text Password Storage Vulnerability in Dell Wyse Management Suite 3.6.1 and below contains an Plain-text Password Storage Vulnerability in UI. An attacker with low privileges could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials to access the vulnerable application with privileges of the c
nvd
CVE-2026-49506P3HIGHCVSS 7.2fixed in 5.5v5.5+1 more2026-06-25
CVE-2026-49506 [HIGH] CWE-22 CVE-2026-49506: Dell Wyse Management Suite, versions prior to WMS 5.5 HF1, contain an Improper Limitation of a Pathn Dell Wyse Management Suite, versions prior to WMS 5.5 HF1, contain an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote Code Execution.
nvd
CVE-2025-36574P3HIGHCVSS 8.2fixed in 5.2≥ N/A, < 5.22025-06-10
CVE-2025-36574 [HIGH] CWE-36 CVE-2025-36574: Dell Wyse Management Suite, versions prior to WMS 5.2, contain an Absolute Path Traversal vulnerabil Dell Wyse Management Suite, versions prior to WMS 5.2, contain an Absolute Path Traversal vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure and Unauthorized access.
nvd
CVE-2026-22766P3HIGHCVSS 7.2fixed in 5.5fixed in 5.5*2026-02-24
CVE-2026-22766 [HIGH] CWE-434 CVE-2026-22766: Dell Wyse Management Suite, versions prior to WMS 5.5, contain an Unrestricted Upload of File with D Dell Wyse Management Suite, versions prior to WMS 5.5, contain an Unrestricted Upload of File with Dangerous Type vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.
nvd
CVE-2025-36575P3HIGHCVSS 7.5fixed in 5.2≥ N/A, < 5.22025-06-10
CVE-2025-36575 [HIGH] CWE-202 CVE-2025-36575: Dell Wyse Management Suite, versions prior to WMS 5.2, contain an Exposure of Sensitive Information Dell Wyse Management Suite, versions prior to WMS 5.2, contain an Exposure of Sensitive Information Through Data Queries vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.
nvd
CVE-2024-49597P3HIGHCVSS 7.2≤ 4.4≥ N/A, ≤ 4.42024-11-26
CVE-2024-49597 [HIGH] CWE-307 CVE-2024-49597: Dell Wyse Management Suite, versions WMS 4.4 and prior, contain an Improper Restriction of Excessive Dell Wyse Management Suite, versions WMS 4.4 and prior, contain an Improper Restriction of Excessive Authentication Attempts vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Protection mechanism bypass.
nvd
CVE-2022-23155P3HIGHCVSS 7.2≥ 2.0, ≤ 3.5.2≥ unspecified, < 3.62022-04-01
CVE-2022-23155 [HIGH] CWE-434 CVE-2022-23155: Dell Wyse Management Suite versions 2.0 through 3.5.2 contain an unrestricted file upload vulnerabil Dell Wyse Management Suite versions 2.0 through 3.5.2 contain an unrestricted file upload vulnerability. A malicious user with admin privileges can exploit this vulnerability in order to execute arbitrary code on the system.
nvd
CVE-2025-29981P3HIGHCVSS 7.5fixed in 5.1≥ N/A, < 5.12025-04-02
CVE-2025-29981 [HIGH] CWE-202 CVE-2025-29981: Dell Wyse Management Suite, versions prior to WMS 5.1, contains an Exposure of Sensitive Information Dell Wyse Management Suite, versions prior to WMS 5.1, contains an Exposure of Sensitive Information Through Data Queries vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.
nvd
CVE-2026-44274P3HIGHCVSS 7.8fixed in 26052026-06-22
CVE-2026-44274 [HIGH] CWE-59 CVE-2026-44274: Dell Wyse Management Suite (WMS), versions prior to WMS 2605, contain an Improper Link Resolution Be Dell Wyse Management Suite (WMS), versions prior to WMS 2605, contain an Improper Link Resolution Before File Access vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Unauthorized access.
nvd
CVE-2025-27694P3HIGHCVSS 7.5fixed in 5.1≥ N/A, < 5.12025-04-02
CVE-2025-27694 [HIGH] CWE-410 CVE-2025-27694: Dell Wyse Management Suite, versions prior to WMS 5.1, contains an Insufficient Resource Pool vulne Dell Wyse Management Suite, versions prior to WMS 5.1, contains an Insufficient Resource Pool vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Denial of service.
nvd
CVE-2025-27692P3HIGHCVSS 7.2fixed in 5.12025-04-02
CVE-2025-27692 [HIGH] CWE-434 CVE-2025-27692: Dell Wyse Management Suite, versions prior to WMS 5.1, contains an Unrestricted Upload of File with Dell Wyse Management Suite, versions prior to WMS 5.1, contains an Unrestricted Upload of File with Dangerous Type vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Denial of service, Information disclosure, and Remote execution
nvd
CVE-2018-11063P3HIGHCVSS 7.8≤ 1.1≥ Standard, ≤ 1.1+1 more2018-08-10
CVE-2018-11063 [HIGH] CWE-428 CVE-2018-11063: Dell WMS versions 1.1 and prior are impacted by multiple unquoted service path vulnerabilities. Affe Dell WMS versions 1.1 and prior are impacted by multiple unquoted service path vulnerabilities. Affected software installs multiple services incorrectly by specifying the paths to the service executables without quotes. This could potentially allow a low-privileged local user to execute arbitrary executables with elevated privileges.
nvd
CVE-2022-33930P3HIGHCVSS 7.5fixed in 3.8.0≥ unspecified, < 3.72022-08-10
CVE-2022-33930 [HIGH] CWE-209 CVE-2022-33930: Dell Wyse Management Suite 3.6.1 and below contains Information Disclosure in Devices error pages. A Dell Wyse Management Suite 3.6.1 and below contains Information Disclosure in Devices error pages. An attacker could potentially exploit this vulnerability, leading to the disclosure of certain sensitive information. The attacker may be able to use the exposed information to access and further vulnerability research.
nvd
CVE-2025-36578P3MEDIUMCVSS 6.8fixed in 5.2≥ N/A, < 5.22025-06-10
CVE-2025-36578 [MEDIUM] CWE-863 CVE-2025-36578: Dell Wyse Management Suite, versions prior to WMS 5.2, contain an Incorrect Authorization vulnerabil Dell Wyse Management Suite, versions prior to WMS 5.2, contain an Incorrect Authorization vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.
nvd
Dell Wyse Management Suite vulnerabilities | cvebase