Dell Wyse Management Suite vulnerabilities
70 known vulnerabilities affecting dell/wyse_management_suite.
Total CVEs
70
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL6HIGH21MEDIUM40LOW3
Vulnerabilities
Page 2 of 4
CVE-2026-44274P3HIGHCVSS 7.8fixed in 26052026-06-22
CVE-2026-44274 [HIGH] CWE-59 CVE-2026-44274: Dell Wyse Management Suite (WMS), versions prior to WMS 2605, contain an Improper Link Resolution Be
Dell Wyse Management Suite (WMS), versions prior to WMS 2605, contain an Improper Link Resolution Before File Access vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Unauthorized access.
nvd
CVE-2026-63701P3HIGHCVSS 7.8fixed in 2605.0.22026-08-14
CVE-2026-63701 [HIGH] CWE-269 CVE-2026-63701: Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Improper Deserialization of
Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Improper Deserialization of Untrusted Data vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Privilege Escalation.
nvd
CVE-2022-23155P3HIGHCVSS 7.2≥ 2.0, ≤ 3.5.2≥ unspecified, < 3.62022-04-01
CVE-2022-23155 [HIGH] CWE-434 CVE-2022-23155: Dell Wyse Management Suite versions 2.0 through 3.5.2 contain an unrestricted file upload vulnerabil
Dell Wyse Management Suite versions 2.0 through 3.5.2 contain an unrestricted file upload vulnerability. A malicious user with admin privileges can exploit this vulnerability in order to execute arbitrary code on the system.
nvd
CVE-2026-81237P3MEDIUMCVSS 6.5fixed in 2605.0.3.683fixed in WMS 2605.0.3.6832026-09-15
CVE-2026-81237 [MEDIUM] CWE-287 CVE-2026-81237: Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Improper Authentication vulne
Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Improper Authentication vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.
nvd
CVE-2025-27694P3HIGHCVSS 7.5fixed in 5.1≥ N/A, < 5.12025-04-02
CVE-2025-27694 [HIGH] CWE-410 CVE-2025-27694: Dell Wyse Management Suite, versions prior to WMS 5.1, contains an Insufficient Resource Pool vulne
Dell Wyse Management Suite, versions prior to WMS 5.1, contains an Insufficient Resource Pool vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Denial of service.
nvd
CVE-2025-27692P3HIGHCVSS 7.2fixed in 5.12025-04-02
CVE-2025-27692 [HIGH] CWE-434 CVE-2025-27692: Dell Wyse Management Suite, versions prior to WMS 5.1, contains an Unrestricted Upload of File with
Dell Wyse Management Suite, versions prior to WMS 5.1, contains an Unrestricted Upload of File with Dangerous Type vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Denial of service, Information disclosure, and Remote execution
nvd
CVE-2018-11063P3HIGHCVSS 7.8≤ 1.1≥ Standard, ≤ 1.1+1 more2018-08-10
CVE-2018-11063 [HIGH] CWE-428 CVE-2018-11063: Dell WMS versions 1.1 and prior are impacted by multiple unquoted service path vulnerabilities. Affe
Dell WMS versions 1.1 and prior are impacted by multiple unquoted service path vulnerabilities. Affected software installs multiple services incorrectly by specifying the paths to the service executables without quotes. This could potentially allow a low-privileged local user to execute arbitrary executables with elevated privileges.
nvd
CVE-2022-33930P3HIGHCVSS 7.5fixed in 3.8.0≥ unspecified, < 3.72022-08-10
CVE-2022-33930 [HIGH] CWE-209 CVE-2022-33930: Dell Wyse Management Suite 3.6.1 and below contains Information Disclosure in Devices error pages. A
Dell Wyse Management Suite 3.6.1 and below contains Information Disclosure in Devices error pages. An attacker could potentially exploit this vulnerability, leading to the disclosure of certain sensitive information. The attacker may be able to use the exposed information to access and further vulnerability research.
nvd
CVE-2025-36578P3MEDIUMCVSS 6.8fixed in 5.2≥ N/A, < 5.22025-06-10
CVE-2025-36578 [MEDIUM] CWE-863 CVE-2025-36578: Dell Wyse Management Suite, versions prior to WMS 5.2, contain an Incorrect Authorization vulnerabil
Dell Wyse Management Suite, versions prior to WMS 5.2, contain an Incorrect Authorization vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.
nvd
CVE-2022-34365P3MEDIUMCVSS 6.5fixed in 3.8.0≥ unspecified, < 3.82022-08-10
CVE-2022-34365 [MEDIUM] CWE-22 CVE-2022-34365: WMS 3.7 contains a Path Traversal Vulnerability in Device API. An attacker could potentially exploit
WMS 3.7 contains a Path Traversal Vulnerability in Device API. An attacker could potentially exploit this vulnerability, to gain unauthorized read access to the files stored on the server filesystem, with the privileges of the running web application.
nvd
CVE-2022-33925P3MEDIUMCVSS 6.5fixed in 3.8.0≥ unspecified, < 3.72022-08-10
CVE-2022-33925 [MEDIUM] CWE-284 CVE-2022-33925: Dell Wyse Management Suite 3.6.1 and below contains an Improper Access control vulnerability in UI.
Dell Wyse Management Suite 3.6.1 and below contains an Improper Access control vulnerability in UI. An remote authenticated attacker could potentially exploit this vulnerability by bypassing access controls in order to download reports containing sensitive information.
nvd
CVE-2021-21587P4LOWCVSS 3.3PoC≤ 3.2≥ unspecified, < 3.32021-07-15
CVE-2021-21587 [LOW] CWE-200 CVE-2021-21587: Dell Wyse Management Suite versions 3.2 and earlier contain a full path disclosure vulnerability. A
Dell Wyse Management Suite versions 3.2 and earlier contain a full path disclosure vulnerability. A local unauthenticated attacker could exploit this vulnerability in order to obtain the path of files and folders.
nvd
CVE-2021-36337P3HIGHCVSS 7.4≤ 3.3.1≥ unspecified, < 3.52021-12-21
CVE-2021-36337 [HIGH] CWE-326 CVE-2021-36337: Dell Wyse Management Suite version 3.3.1 and prior support insecure Transport Security Protocols TLS
Dell Wyse Management Suite version 3.3.1 and prior support insecure Transport Security Protocols TLS 1.0 and TLS 1.1 which are susceptible to Man-In-The-Middle attacks thereby compromising Confidentiality and Integrity of data.
nvd
CVE-2022-33926P3MEDIUMCVSS 6.5fixed in 3.8.0≥ unspecified, < 3.72022-08-10
CVE-2022-33926 [MEDIUM] CWE-284 CVE-2022-33926: Dell Wyse Management Suite 3.6.1 and below contains an improper access control vulnerability. A remo
Dell Wyse Management Suite 3.6.1 and below contains an improper access control vulnerability. A remote malicious user could exploit this vulnerability in order to retain access to a file repository after it has been revoked.
nvd
CVE-2022-46754P3MEDIUMCVSS 6.5≤ 3.8.02023-02-11
CVE-2022-46754 [MEDIUM] CWE-284 CVE-2022-46754: Wyse Management Suite 3.8 and below contain an improper access control vulnerability. A authenticat
Wyse Management Suite 3.8 and below contain an improper access control vulnerability. A authenticated malicious admin user might access certain pro license features for which this admin is not authorized in order to configure user controlled external entities.
nvd
CVE-2022-33927P3MEDIUMCVSS 6.5fixed in 3.8.0≥ unspecified, < 3.72022-08-10
CVE-2022-33927 [MEDIUM] CWE-384 CVE-2022-33927: Dell Wyse Management Suite 3.6.1 and below contains a Session Fixation vulnerability. A unauthentica
Dell Wyse Management Suite 3.6.1 and below contains a Session Fixation vulnerability. A unauthenticated attacker could exploit this by taking advantage of a user with multiple active sessions in order to hijack a user's session.
nvd
CVE-2022-29090P3MEDIUMCVSS 6.5fixed in 3.8.0≥ unspecified, < 3.72022-08-10
CVE-2022-29090 [MEDIUM] CWE-317 CVE-2022-29090: Dell Wyse Management Suite 3.6.1 and below contains a Sensitive Data Exposure vulnerability. A low p
Dell Wyse Management Suite 3.6.1 and below contains a Sensitive Data Exposure vulnerability. A low privileged malicious user could potentially exploit this vulnerability in order to obtain credentials. The attacker may be able to use the exposed credentials to access the target device and perform unauthorized actions.
nvd
CVE-2024-49596P3MEDIUMCVSS 6.5≤ 4.4≥ N/A, ≤ 4.42024-11-26
CVE-2024-49596 [MEDIUM] CWE-862 CVE-2024-49596: Dell Wyse Management Suite, version WMS 4.4 and prior, contain a Missing Authorization vulnerability
Dell Wyse Management Suite, version WMS 4.4 and prior, contain a Missing Authorization vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Denial of service and arbitrary file deletion
nvd
CVE-2026-66272P4MEDIUMCVSS 5.3fixed in 2605.0.22026-08-14
CVE-2026-66272 [MEDIUM] CWE-200 CVE-2026-66272: Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain a Missing Authentication for C
Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.
nvd
CVE-2023-32481P4MEDIUMCVSS 6.5fixed in 4.0v4.0 and below2023-07-20
CVE-2023-32481 [MEDIUM] CWE-770 CVE-2023-32481: Wyse Management Suite versions prior to 4.0 contain a denial-of-service vulnerability. An authentic
Wyse Management Suite versions prior to 4.0 contain a denial-of-service vulnerability. An authenticated malicious user can flood the configured SMTP server with numerous requests in order to deny access to the system.
nvd