Dell Wyse Management Suite vulnerabilities
58 known vulnerabilities affecting dell/wyse_management_suite.
Total CVEs
58
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH17MEDIUM36LOW3
Vulnerabilities
Page 3 of 3
CVE-2022-29096P4MEDIUMCVSS 5.4≤ 3.6.1≥ unspecified, < 3.6.12022-06-24
CVE-2022-29096 [MEDIUM] CWE-79 CVE-2022-29096: Dell Wyse Management Suite 3.6.1 and below contains a Reflected Cross-Site Scripting Vulnerability i
Dell Wyse Management Suite 3.6.1 and below contains a Reflected Cross-Site Scripting Vulnerability in saveGroupConfigurations page. An authenticated attacker could potentially exploit this vulnerability, leading to the execution of malicious HTML or JavaScript code in a victim user's web browser in the context of the vulnerable web application. Explo
nvd
CVE-2022-46675P4MEDIUMCVSS 5.3≤ 3.82023-02-11
CVE-2022-46675 [MEDIUM] CWE-209 CVE-2022-46675: Wyse Management Suite Repository 3.8 and below contain an information disclosure vulnerability. A u
Wyse Management Suite Repository 3.8 and below contain an information disclosure vulnerability. A unauthenticated attacker could potentially discover the internal structure of the application and its components and use this information for further vulnerability research.
nvd
CVE-2026-23858P4MEDIUMCVSS 5.4fixed in 5.5≥ N/A, < 5.52026-02-24
CVE-2026-23858 [MEDIUM] CWE-79 CVE-2026-23858: Dell Wyse Management Suite, versions prior to WMS 5.5, contain an Improper Neutralization of Input D
Dell Wyse Management Suite, versions prior to WMS 5.5, contain an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Script Injection.
nvd
CVE-2023-32482P4MEDIUMCVSS 4.9fixed in 4.0v4.0 and below2023-07-20
CVE-2023-32482 [MEDIUM] CWE-285 CVE-2023-32482: Wyse Management Suite versions prior to 4.0 contain an improper authorization vulnerability. An aut
Wyse Management Suite versions prior to 4.0 contain an improper authorization vulnerability. An authenticated malicious user with privileged access can push policies to unauthorized tenant group.
nvd
CVE-2025-36577P4MEDIUMCVSS 6.1fixed in 5.2≥ N/A, < 5.22025-06-10
CVE-2025-36577 [MEDIUM] CWE-79 CVE-2025-36577: Dell Wyse Management Suite, versions prior to WMS 5.2, contain an Improper Neutralization of Input D
Dell Wyse Management Suite, versions prior to WMS 5.2, contain an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Script injection.
nvd
CVE-2022-46678P4MEDIUMCVSS 4.9≤ 3.8.02023-02-11
CVE-2022-46678 [MEDIUM] CWE-284 CVE-2022-46678: Wyse Management Suite 3.8 and below contain an improper access control vulnerability. A authent
Wyse Management Suite
3.8 and below contain an improper access control vulnerability. A authenticated malicious admin user can edit general client policy for which the user is not authorized.
nvd
CVE-2022-46677P4MEDIUMCVSS 4.9≤ 3.8.02023-02-11
CVE-2022-46677 [MEDIUM] CWE-284 CVE-2022-46677: Wyse Management Suite 3.8 and below contain an improper access control vulnerability with which an
Wyse Management Suite 3.8 and below contain an improper access control vulnerability with which an custom group admin can create a subgroup under a group for which the admin is not authorized.
nvd
CVE-2022-46676P4MEDIUMCVSS 4.9≤ 3.8.02023-02-11
CVE-2022-46676 [MEDIUM] CWE-284 CVE-2022-46676: Wyse Management Suite 3.8 and below contain an improper access control vulnerability. A malicious a
Wyse Management Suite 3.8 and below contain an improper access control vulnerability. A malicious admin user can disable or delete users under administration and unassigned admins for which the group admin is not authorized.
nvd
CVE-2022-46755P4MEDIUMCVSS 4.9≤ 3.8.02023-02-11
CVE-2022-46755 [MEDIUM] CWE-284 CVE-2022-46755: Wyse Management Suite 3.8 and below contain an improper access control vulnerability. A authenticat
Wyse Management Suite 3.8 and below contain an improper access control vulnerability. A authenticated malicious admin user can edit general client policy for which the user is not authorized.
nvd
CVE-2024-49595P4MEDIUMCVSS 4.9≤ 4.4≥ N/A, ≤ 4.42024-11-26
CVE-2024-49595 [MEDIUM] CWE-294 CVE-2024-49595: Dell Wyse Management Suite, version WMS 4.4 and before, contain an Authentication Bypass by Capture-
Dell Wyse Management Suite, version WMS 4.4 and before, contain an Authentication Bypass by Capture-replay vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Denial of service.
nvd
CVE-2020-29496P4MEDIUMCVSS 4.8fixed in 3.1≥ unspecified, < 3.12021-01-04
CVE-2020-29496 [MEDIUM] CWE-79 CVE-2020-29496: Dell Wyse Management Suite versions prior to 3.1 contain a stored cross-site scripting vulnerability
Dell Wyse Management Suite versions prior to 3.1 contain a stored cross-site scripting vulnerability. A remote authenticated malicious user with high privileges could exploit this vulnerability to store malicious HTML or JavaScript code while creating the Enduser. When victim users access the submitted data through their browsers, the malicious code
nvd
CVE-2025-36580P4MEDIUMCVSS 4.8fixed in 5.2≥ N/A, < 5.22025-06-10
CVE-2025-36580 [MEDIUM] CWE-79 CVE-2025-36580: Dell Wyse Management Suite, versions prior to WMS 5.2, contain an Improper Neutralization of Input D
Dell Wyse Management Suite, versions prior to WMS 5.2, contain an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Script injection
nvd
CVE-2025-27693P4MEDIUMCVSS 4.8fixed in 5.1≥ N/A, < 5.12025-04-02
CVE-2025-27693 [MEDIUM] CWE-79 CVE-2025-27693: Dell Wyse Management Suite, versions prior to WMS 5.1, contains an Improper Neutralization of Input
Dell Wyse Management Suite, versions prior to WMS 5.1, contains an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Script injection.
nvd
CVE-2021-21533P4MEDIUMCVSS 4.3fixed in 3.2≥ unspecified, < 3.22021-04-02
CVE-2021-21533 [MEDIUM] CWE-20 CVE-2021-21533: Wyse Management Suite versions up to 3.2 contains a vulnerability wherein a malicious authenticated
Wyse Management Suite versions up to 3.2 contains a vulnerability wherein a malicious authenticated user can cause a denial of service in the job status retrieval page, also affecting other users that would have normally access to the same subset of job details
nvd
CVE-2026-44273P4MEDIUMCVSS 4.4fixed in 26052026-06-22
CVE-2026-44273 [MEDIUM] CWE-1392 CVE-2026-44273: Dell Wyse Management Suite (WMS), versions prior to WMS 2605, contain a Use of Default Credentials v
Dell Wyse Management Suite (WMS), versions prior to WMS 2605, contain a Use of Default Credentials vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Information Disclosure.
nvd
CVE-2023-32483P4MEDIUMCVSS 4.4fixed in 4.0v4.0 and below2023-07-20
CVE-2023-32483 [MEDIUM] CWE-312 CVE-2023-32483: Wyse Management Suite versions prior to 4.0 contain a sensitive information disclosure vulnerabilit
Wyse Management Suite versions prior to 4.0 contain a sensitive information disclosure vulnerability. An authenticated malicious user having local access to the system running the application could exploit this vulnerability to read sensitive information written to log files.
nvd
CVE-2026-23859P4LOWCVSS 2.7fixed in 5.5≥ N/A, < 5.52026-02-24
CVE-2026-23859 [LOW] CWE-602 CVE-2026-23859: Dell Wyse Management Suite, versions prior to WMS 5.5, contain a Client-Side Enforcement of Server-S
Dell Wyse Management Suite, versions prior to WMS 5.5, contain a Client-Side Enforcement of Server-Side Security vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability to Protection mechanism bypass.
nvd
CVE-2025-36576P4LOWCVSS 2.7fixed in 5.2≥ N/A, < 5.22025-06-10
CVE-2025-36576 [LOW] CWE-352 CVE-2025-36576: Dell Wyse Management Suite, versions prior to WMS 5.2, contain a Cross-Site Request Forgery (CSRF) v
Dell Wyse Management Suite, versions prior to WMS 5.2, contain a Cross-Site Request Forgery (CSRF) vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Server-side request forgery.
nvd
← Previous3 / 3