Dell Wyse Management Suite vulnerabilities
70 known vulnerabilities affecting dell/wyse_management_suite.
Total CVEs
70
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL6HIGH21MEDIUM40LOW3
Vulnerabilities
Page 3 of 4
CVE-2019-3769P4MEDIUMCVSS 6.4fixed in 1.4.1≥ unspecified, < WMS 1.4.12020-03-13
CVE-2019-3769 [MEDIUM] CWE-79 CVE-2019-3769: Dell Wyse Management Suite versions prior to 1.4.1 contain a stored cross-site scripting vulnerabili
Dell Wyse Management Suite versions prior to 1.4.1 contain a stored cross-site scripting vulnerability. A remote authenticated malicious user with low privileges could exploit this vulnerability to store malicious payload in the device heartbeat request. When victim users access the submitted data through their browsers, the malicious code gets execute
nvd
CVE-2019-3770P4MEDIUMCVSS 6.4fixed in 1.4.1≥ unspecified, < WMS 1.4.12020-03-13
CVE-2019-3770 [MEDIUM] CWE-79 CVE-2019-3770: Dell Wyse Management Suite versions prior to 1.4.1 contain a stored cross-site scripting vulnerabili
Dell Wyse Management Suite versions prior to 1.4.1 contain a stored cross-site scripting vulnerability when unregistering a device. A remote authenticated malicious user with low privileges could exploit this vulnerability to store malicious HTML or JavaScript code. When victim users access the submitted data through their browsers, the malicious code
nvd
CVE-2022-29097P4MEDIUMCVSS 4.9≤ 3.6.1≥ unspecified, < 3.6.12022-06-24
CVE-2022-29097 [MEDIUM] CWE-23 CVE-2022-29097: Dell WMS 3.6.1 and below contains a Path Traversal vulnerability in Device API. A remote attacker co
Dell WMS 3.6.1 and below contains a Path Traversal vulnerability in Device API. A remote attacker could potentially exploit this vulnerability, to gain unauthorized read access to the files stored on the server filesystem, with the privileges of the running web application.
nvd
CVE-2025-29982P4MEDIUMCVSS 6.8fixed in 5.1≥ N/A, < 5.12025-04-02
CVE-2025-29982 [MEDIUM] CWE-277 CVE-2025-29982: Dell Wyse Management Suite, versions prior to WMS 5.1, contains an Insecure Inherited Permissions vu
Dell Wyse Management Suite, versions prior to WMS 5.1, contains an Insecure Inherited Permissions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Unauthorized access.
nvd
CVE-2022-33924P4MEDIUMCVSS 5.3fixed in 3.8.0≥ unspecified, < 3.72022-08-10
CVE-2022-33924 [MEDIUM] CWE-284 CVE-2022-33924: Dell Wyse Management Suite 3.6.1 and below contains an Improper Access control vulnerability with wh
Dell Wyse Management Suite 3.6.1 and below contains an Improper Access control vulnerability with which an attacker with no access to create rules could potentially exploit this vulnerability and create rules.
nvd
CVE-2022-33931P4MEDIUMCVSS 5.3fixed in 3.8.0≥ unspecified, < 3.72022-08-10
CVE-2022-33931 [MEDIUM] CWE-284 CVE-2022-33931: Dell Wyse Management Suite 3.6.1 and below contains an Improper Access control vulnerability in UI.
Dell Wyse Management Suite 3.6.1 and below contains an Improper Access control vulnerability in UI. An attacker with no access to Alert Classification page could potentially exploit this vulnerability, leading to the change the alert categories.
nvd
CVE-2020-29498P4MEDIUMCVSS 6.1fixed in 3.1≥ unspecified, < 3.12021-01-04
CVE-2020-29498 [MEDIUM] CWE-601 CVE-2020-29498: Dell Wyse Management Suite versions prior to 3.1 contain an open redirect vulnerability. A remote un
Dell Wyse Management Suite versions prior to 3.1 contain an open redirect vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability to redirect application users to arbitrary web URLs by tricking the victim users to click on maliciously crafted links. The vulnerability could be used to conduct phishing attacks tha
nvd
CVE-2026-63702P4MEDIUMCVSS 5.5fixed in 2605.0.22026-08-14
CVE-2026-63702 [MEDIUM] CWE-798 CVE-2026-63702: Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain a Use of Hard-coded Credential
Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain a Use of Hard-coded Credentials vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Unauthorized access.
nvd
CVE-2025-27695P4MEDIUMCVSS 4.9fixed in 5.1≥ N/A, < 5.12025-05-08
CVE-2025-27695 [MEDIUM] CWE-290 CVE-2025-27695: Dell Wyse Management Suite, versions prior to WMS 5.1 contain an Authentication Bypass by Spoofing v
Dell Wyse Management Suite, versions prior to WMS 5.1 contain an Authentication Bypass by Spoofing vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Information Disclosure.
nvd
CVE-2022-33929P4MEDIUMCVSS 6.1fixed in 3.8.0≥ unspecified, < 3.72022-08-10
CVE-2022-33929 [MEDIUM] CWE-79 CVE-2022-33929: Dell Wyse Management Suite 3.6.1 and below contains a Reflected Cross-Site Scripting Vulnerability i
Dell Wyse Management Suite 3.6.1 and below contains a Reflected Cross-Site Scripting Vulnerability in EndUserSummary page. An authenticated attacker could potentially exploit this vulnerability, leading to the execution of malicious HTML or JavaScript code in a victim user's web browser in the context of the vulnerable web application. Exploitation m
nvd
CVE-2022-29096P4MEDIUMCVSS 5.4≤ 3.6.1≥ unspecified, < 3.6.12022-06-24
CVE-2022-29096 [MEDIUM] CWE-79 CVE-2022-29096: Dell Wyse Management Suite 3.6.1 and below contains a Reflected Cross-Site Scripting Vulnerability i
Dell Wyse Management Suite 3.6.1 and below contains a Reflected Cross-Site Scripting Vulnerability in saveGroupConfigurations page. An authenticated attacker could potentially exploit this vulnerability, leading to the execution of malicious HTML or JavaScript code in a victim user's web browser in the context of the vulnerable web application. Explo
nvd
CVE-2022-46675P4MEDIUMCVSS 5.3≤ 3.82023-02-11
CVE-2022-46675 [MEDIUM] CWE-209 CVE-2022-46675: Wyse Management Suite Repository 3.8 and below contain an information disclosure vulnerability. A u
Wyse Management Suite Repository 3.8 and below contain an information disclosure vulnerability. A unauthenticated attacker could potentially discover the internal structure of the application and its components and use this information for further vulnerability research.
nvd
CVE-2026-81235P4MEDIUMCVSS 4.9fixed in 2605.0.3.683fixed in WMS 2605.0.3.6832026-09-15
CVE-2026-81235 [MEDIUM] CWE-325 CVE-2026-81235: Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain a Missing Cryptographic Step vul
Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain a Missing Cryptographic Step vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Information tampering.
nvd
CVE-2025-36577P4MEDIUMCVSS 6.1fixed in 5.2≥ N/A, < 5.22025-06-10
CVE-2025-36577 [MEDIUM] CWE-79 CVE-2025-36577: Dell Wyse Management Suite, versions prior to WMS 5.2, contain an Improper Neutralization of Input D
Dell Wyse Management Suite, versions prior to WMS 5.2, contain an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Script injection.
nvd
CVE-2020-29497P4MEDIUMCVSS 5.4fixed in 3.1≥ unspecified, < 3.12021-01-04
CVE-2020-29497 [MEDIUM] CWE-79 CVE-2020-29497: Dell Wyse Management Suite versions prior to 3.1 contain a stored cross-site scripting vulnerability
Dell Wyse Management Suite versions prior to 3.1 contain a stored cross-site scripting vulnerability. A remote authenticated malicious user with low privileges could exploit this vulnerability to store malicious HTML or JavaScript code under the device tag. When victim users access the submitted data through their browsers, the malicious code gets ex
nvd
CVE-2026-23858P4MEDIUMCVSS 5.4fixed in 5.5≥ N/A, < 5.52026-02-24
CVE-2026-23858 [MEDIUM] CWE-79 CVE-2026-23858: Dell Wyse Management Suite, versions prior to WMS 5.5, contain an Improper Neutralization of Input D
Dell Wyse Management Suite, versions prior to WMS 5.5, contain an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Script Injection.
nvd
CVE-2023-32482P4MEDIUMCVSS 4.9fixed in 4.0v4.0 and below2023-07-20
CVE-2023-32482 [MEDIUM] CWE-285 CVE-2023-32482: Wyse Management Suite versions prior to 4.0 contain an improper authorization vulnerability. An aut
Wyse Management Suite versions prior to 4.0 contain an improper authorization vulnerability. An authenticated malicious user with privileged access can push policies to unauthorized tenant group.
nvd
CVE-2022-46678P4MEDIUMCVSS 4.9≤ 3.8.02023-02-11
CVE-2022-46678 [MEDIUM] CWE-284 CVE-2022-46678: Wyse Management Suite 3.8 and below contain an improper access control vulnerability. A authent
Wyse Management Suite
3.8 and below contain an improper access control vulnerability. A authenticated malicious admin user can edit general client policy for which the user is not authorized.
nvd
CVE-2022-46677P4MEDIUMCVSS 4.9≤ 3.8.02023-02-11
CVE-2022-46677 [MEDIUM] CWE-284 CVE-2022-46677: Wyse Management Suite 3.8 and below contain an improper access control vulnerability with which an
Wyse Management Suite 3.8 and below contain an improper access control vulnerability with which an custom group admin can create a subgroup under a group for which the admin is not authorized.
nvd
CVE-2022-46676P4MEDIUMCVSS 4.9≤ 3.8.02023-02-11
CVE-2022-46676 [MEDIUM] CWE-284 CVE-2022-46676: Wyse Management Suite 3.8 and below contain an improper access control vulnerability. A malicious a
Wyse Management Suite 3.8 and below contain an improper access control vulnerability. A malicious admin user can disable or delete users under administration and unassigned admins for which the group admin is not authorized.
nvd