cbcvebase.

Dell Wyse Management Suite vulnerabilities

58 known vulnerabilities affecting dell/wyse_management_suite.

Total CVEs
58
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH17MEDIUM36LOW3

Vulnerabilities

Page 2 of 3
CVE-2022-34365P3MEDIUMCVSS 6.5fixed in 3.8.0≥ unspecified, < 3.82022-08-10
CVE-2022-34365 [MEDIUM] CWE-22 CVE-2022-34365: WMS 3.7 contains a Path Traversal Vulnerability in Device API. An attacker could potentially exploit WMS 3.7 contains a Path Traversal Vulnerability in Device API. An attacker could potentially exploit this vulnerability, to gain unauthorized read access to the files stored on the server filesystem, with the privileges of the running web application.
nvd
CVE-2022-33925P3MEDIUMCVSS 6.5fixed in 3.8.0≥ unspecified, < 3.72022-08-10
CVE-2022-33925 [MEDIUM] CWE-284 CVE-2022-33925: Dell Wyse Management Suite 3.6.1 and below contains an Improper Access control vulnerability in UI. Dell Wyse Management Suite 3.6.1 and below contains an Improper Access control vulnerability in UI. An remote authenticated attacker could potentially exploit this vulnerability by bypassing access controls in order to download reports containing sensitive information.
nvd
CVE-2021-21587P4LOWCVSS 3.3PoC≤ 3.2≥ unspecified, < 3.32021-07-15
CVE-2021-21587 [LOW] CWE-200 CVE-2021-21587: Dell Wyse Management Suite versions 3.2 and earlier contain a full path disclosure vulnerability. A Dell Wyse Management Suite versions 3.2 and earlier contain a full path disclosure vulnerability. A local unauthenticated attacker could exploit this vulnerability in order to obtain the path of files and folders.
nvd
CVE-2021-36337P3HIGHCVSS 7.4≤ 3.3.1≥ unspecified, < 3.52021-12-21
CVE-2021-36337 [HIGH] CWE-326 CVE-2021-36337: Dell Wyse Management Suite version 3.3.1 and prior support insecure Transport Security Protocols TLS Dell Wyse Management Suite version 3.3.1 and prior support insecure Transport Security Protocols TLS 1.0 and TLS 1.1 which are susceptible to Man-In-The-Middle attacks thereby compromising Confidentiality and Integrity of data.
nvd
CVE-2022-33926P3MEDIUMCVSS 6.5fixed in 3.8.0≥ unspecified, < 3.72022-08-10
CVE-2022-33926 [MEDIUM] CWE-284 CVE-2022-33926: Dell Wyse Management Suite 3.6.1 and below contains an improper access control vulnerability. A remo Dell Wyse Management Suite 3.6.1 and below contains an improper access control vulnerability. A remote malicious user could exploit this vulnerability in order to retain access to a file repository after it has been revoked.
nvd
CVE-2022-46754P3MEDIUMCVSS 6.5≤ 3.8.02023-02-11
CVE-2022-46754 [MEDIUM] CWE-284 CVE-2022-46754: Wyse Management Suite 3.8 and below contain an improper access control vulnerability. A authenticat Wyse Management Suite 3.8 and below contain an improper access control vulnerability. A authenticated malicious admin user might access certain pro license features for which this admin is not authorized in order to configure user controlled external entities.
nvd
CVE-2024-49596P3MEDIUMCVSS 6.5≤ 4.4≥ N/A, ≤ 4.42024-11-26
CVE-2024-49596 [MEDIUM] CWE-862 CVE-2024-49596: Dell Wyse Management Suite, version WMS 4.4 and prior, contain a Missing Authorization vulnerability Dell Wyse Management Suite, version WMS 4.4 and prior, contain a Missing Authorization vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Denial of service and arbitrary file deletion
nvd
CVE-2022-33927P3MEDIUMCVSS 6.5fixed in 3.8.0≥ unspecified, < 3.72022-08-10
CVE-2022-33927 [MEDIUM] CWE-384 CVE-2022-33927: Dell Wyse Management Suite 3.6.1 and below contains a Session Fixation vulnerability. A unauthentica Dell Wyse Management Suite 3.6.1 and below contains a Session Fixation vulnerability. A unauthenticated attacker could exploit this by taking advantage of a user with multiple active sessions in order to hijack a user's session.
nvd
CVE-2022-29090P3MEDIUMCVSS 6.5fixed in 3.8.0≥ unspecified, < 3.72022-08-10
CVE-2022-29090 [MEDIUM] CWE-317 CVE-2022-29090: Dell Wyse Management Suite 3.6.1 and below contains a Sensitive Data Exposure vulnerability. A low p Dell Wyse Management Suite 3.6.1 and below contains a Sensitive Data Exposure vulnerability. A low privileged malicious user could potentially exploit this vulnerability in order to obtain credentials. The attacker may be able to use the exposed credentials to access the target device and perform unauthorized actions.
nvd
CVE-2023-32481P4MEDIUMCVSS 6.5fixed in 4.0v4.0 and below2023-07-20
CVE-2023-32481 [MEDIUM] CWE-770 CVE-2023-32481: Wyse Management Suite versions prior to 4.0 contain a denial-of-service vulnerability. An authentic Wyse Management Suite versions prior to 4.0 contain a denial-of-service vulnerability. An authenticated malicious user can flood the configured SMTP server with numerous requests in order to deny access to the system.
nvd
CVE-2019-3769P4MEDIUMCVSS 6.4fixed in 1.4.1≥ unspecified, < WMS 1.4.12020-03-13
CVE-2019-3769 [MEDIUM] CWE-79 CVE-2019-3769: Dell Wyse Management Suite versions prior to 1.4.1 contain a stored cross-site scripting vulnerabili Dell Wyse Management Suite versions prior to 1.4.1 contain a stored cross-site scripting vulnerability. A remote authenticated malicious user with low privileges could exploit this vulnerability to store malicious payload in the device heartbeat request. When victim users access the submitted data through their browsers, the malicious code gets execute
nvd
CVE-2019-3770P4MEDIUMCVSS 6.4fixed in 1.4.1≥ unspecified, < WMS 1.4.12020-03-13
CVE-2019-3770 [MEDIUM] CWE-79 CVE-2019-3770: Dell Wyse Management Suite versions prior to 1.4.1 contain a stored cross-site scripting vulnerabili Dell Wyse Management Suite versions prior to 1.4.1 contain a stored cross-site scripting vulnerability when unregistering a device. A remote authenticated malicious user with low privileges could exploit this vulnerability to store malicious HTML or JavaScript code. When victim users access the submitted data through their browsers, the malicious code
nvd
CVE-2022-29097P4MEDIUMCVSS 4.9≤ 3.6.1≥ unspecified, < 3.6.12022-06-24
CVE-2022-29097 [MEDIUM] CWE-23 CVE-2022-29097: Dell WMS 3.6.1 and below contains a Path Traversal vulnerability in Device API. A remote attacker co Dell WMS 3.6.1 and below contains a Path Traversal vulnerability in Device API. A remote attacker could potentially exploit this vulnerability, to gain unauthorized read access to the files stored on the server filesystem, with the privileges of the running web application.
nvd
CVE-2025-29982P4MEDIUMCVSS 6.8fixed in 5.1≥ N/A, < 5.12025-04-02
CVE-2025-29982 [MEDIUM] CWE-277 CVE-2025-29982: Dell Wyse Management Suite, versions prior to WMS 5.1, contains an Insecure Inherited Permissions vu Dell Wyse Management Suite, versions prior to WMS 5.1, contains an Insecure Inherited Permissions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Unauthorized access.
nvd
CVE-2020-29498P4MEDIUMCVSS 6.1fixed in 3.1≥ unspecified, < 3.12021-01-04
CVE-2020-29498 [MEDIUM] CWE-601 CVE-2020-29498: Dell Wyse Management Suite versions prior to 3.1 contain an open redirect vulnerability. A remote un Dell Wyse Management Suite versions prior to 3.1 contain an open redirect vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability to redirect application users to arbitrary web URLs by tricking the victim users to click on maliciously crafted links. The vulnerability could be used to conduct phishing attacks tha
nvd
CVE-2022-33924P4MEDIUMCVSS 5.3fixed in 3.8.0≥ unspecified, < 3.72022-08-10
CVE-2022-33924 [MEDIUM] CWE-284 CVE-2022-33924: Dell Wyse Management Suite 3.6.1 and below contains an Improper Access control vulnerability with wh Dell Wyse Management Suite 3.6.1 and below contains an Improper Access control vulnerability with which an attacker with no access to create rules could potentially exploit this vulnerability and create rules.
nvd
CVE-2022-33931P4MEDIUMCVSS 5.3fixed in 3.8.0≥ unspecified, < 3.72022-08-10
CVE-2022-33931 [MEDIUM] CWE-284 CVE-2022-33931: Dell Wyse Management Suite 3.6.1 and below contains an Improper Access control vulnerability in UI. Dell Wyse Management Suite 3.6.1 and below contains an Improper Access control vulnerability in UI. An attacker with no access to Alert Classification page could potentially exploit this vulnerability, leading to the change the alert categories.
nvd
CVE-2025-27695P4MEDIUMCVSS 4.9fixed in 5.1≥ N/A, < 5.12025-05-08
CVE-2025-27695 [MEDIUM] CWE-290 CVE-2025-27695: Dell Wyse Management Suite, versions prior to WMS 5.1 contain an Authentication Bypass by Spoofing v Dell Wyse Management Suite, versions prior to WMS 5.1 contain an Authentication Bypass by Spoofing vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Information Disclosure.
nvd
CVE-2022-33929P4MEDIUMCVSS 6.1fixed in 3.8.0≥ unspecified, < 3.72022-08-10
CVE-2022-33929 [MEDIUM] CWE-79 CVE-2022-33929: Dell Wyse Management Suite 3.6.1 and below contains a Reflected Cross-Site Scripting Vulnerability i Dell Wyse Management Suite 3.6.1 and below contains a Reflected Cross-Site Scripting Vulnerability in EndUserSummary page. An authenticated attacker could potentially exploit this vulnerability, leading to the execution of malicious HTML or JavaScript code in a victim user's web browser in the context of the vulnerable web application. Exploitation m
nvd
CVE-2020-29497P4MEDIUMCVSS 5.4fixed in 3.1≥ unspecified, < 3.12021-01-04
CVE-2020-29497 [MEDIUM] CWE-79 CVE-2020-29497: Dell Wyse Management Suite versions prior to 3.1 contain a stored cross-site scripting vulnerability Dell Wyse Management Suite versions prior to 3.1 contain a stored cross-site scripting vulnerability. A remote authenticated malicious user with low privileges could exploit this vulnerability to store malicious HTML or JavaScript code under the device tag. When victim users access the submitted data through their browsers, the malicious code gets ex
nvd