cbcvebase.

Dell Wyse Management Suite vulnerabilities

70 known vulnerabilities affecting dell/wyse_management_suite.

Total CVEs
70
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL6HIGH21MEDIUM40LOW3

Vulnerabilities

Page 4 of 4
CVE-2022-46755P4MEDIUMCVSS 4.9≤ 3.8.02023-02-11
CVE-2022-46755 [MEDIUM] CWE-284 CVE-2022-46755: Wyse Management Suite 3.8 and below contain an improper access control vulnerability. A authenticat Wyse Management Suite 3.8 and below contain an improper access control vulnerability. A authenticated malicious admin user can edit general client policy for which the user is not authorized.
nvd
CVE-2024-49595P4MEDIUMCVSS 4.9≤ 4.4≥ N/A, ≤ 4.42024-11-26
CVE-2024-49595 [MEDIUM] CWE-294 CVE-2024-49595: Dell Wyse Management Suite, version WMS 4.4 and before, contain an Authentication Bypass by Capture- Dell Wyse Management Suite, version WMS 4.4 and before, contain an Authentication Bypass by Capture-replay vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Denial of service.
nvd
CVE-2020-29496P4MEDIUMCVSS 4.8fixed in 3.1≥ unspecified, < 3.12021-01-04
CVE-2020-29496 [MEDIUM] CWE-79 CVE-2020-29496: Dell Wyse Management Suite versions prior to 3.1 contain a stored cross-site scripting vulnerability Dell Wyse Management Suite versions prior to 3.1 contain a stored cross-site scripting vulnerability. A remote authenticated malicious user with high privileges could exploit this vulnerability to store malicious HTML or JavaScript code while creating the Enduser. When victim users access the submitted data through their browsers, the malicious code
nvd
CVE-2025-36580P4MEDIUMCVSS 4.8fixed in 5.2≥ N/A, < 5.22025-06-10
CVE-2025-36580 [MEDIUM] CWE-79 CVE-2025-36580: Dell Wyse Management Suite, versions prior to WMS 5.2, contain an Improper Neutralization of Input D Dell Wyse Management Suite, versions prior to WMS 5.2, contain an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Script injection
nvd
CVE-2025-27693P4MEDIUMCVSS 4.8fixed in 5.1≥ N/A, < 5.12025-04-02
CVE-2025-27693 [MEDIUM] CWE-79 CVE-2025-27693: Dell Wyse Management Suite, versions prior to WMS 5.1, contains an Improper Neutralization of Input Dell Wyse Management Suite, versions prior to WMS 5.1, contains an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Script injection.
nvd
CVE-2021-21533P4MEDIUMCVSS 4.3fixed in 3.2≥ unspecified, < 3.22021-04-02
CVE-2021-21533 [MEDIUM] CWE-20 CVE-2021-21533: Wyse Management Suite versions up to 3.2 contains a vulnerability wherein a malicious authenticated Wyse Management Suite versions up to 3.2 contains a vulnerability wherein a malicious authenticated user can cause a denial of service in the job status retrieval page, also affecting other users that would have normally access to the same subset of job details
nvd
CVE-2026-44273P4MEDIUMCVSS 4.4fixed in 26052026-06-22
CVE-2026-44273 [MEDIUM] CWE-1392 CVE-2026-44273: Dell Wyse Management Suite (WMS), versions prior to WMS 2605, contain a Use of Default Credentials v Dell Wyse Management Suite (WMS), versions prior to WMS 2605, contain a Use of Default Credentials vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Information Disclosure.
nvd
CVE-2023-32483P4MEDIUMCVSS 4.4fixed in 4.0v4.0 and below2023-07-20
CVE-2023-32483 [MEDIUM] CWE-312 CVE-2023-32483: Wyse Management Suite versions prior to 4.0 contain a sensitive information disclosure vulnerabilit Wyse Management Suite versions prior to 4.0 contain a sensitive information disclosure vulnerability. An authenticated malicious user having local access to the system running the application could exploit this vulnerability to read sensitive information written to log files.
nvd
CVE-2026-23859P4LOWCVSS 2.7fixed in 5.5≥ N/A, < 5.52026-02-24
CVE-2026-23859 [LOW] CWE-602 CVE-2026-23859: Dell Wyse Management Suite, versions prior to WMS 5.5, contain a Client-Side Enforcement of Server-S Dell Wyse Management Suite, versions prior to WMS 5.5, contain a Client-Side Enforcement of Server-Side Security vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability to Protection mechanism bypass.
nvd
CVE-2025-36576P4LOWCVSS 2.7fixed in 5.2≥ N/A, < 5.22025-06-10
CVE-2025-36576 [LOW] CWE-352 CVE-2025-36576: Dell Wyse Management Suite, versions prior to WMS 5.2, contain a Cross-Site Request Forgery (CSRF) v Dell Wyse Management Suite, versions prior to WMS 5.2, contain a Cross-Site Request Forgery (CSRF) vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Server-side request forgery.
nvd
Dell Wyse Management Suite vulnerabilities | cvebase