Skip to main content
Some article numbers may have changed. If this isn't what you're looking for, try searching all articles. Search articles

DSA-2024-440: Security Update for Dell Wyse Management Suite (WMS) for Multiple Vulnerabilities

Summary: Dell Wyse Management Suite (WMS) remediation is available for multiple vulnerabilities that may be exploited by malicious users to compromise the affected system.

This article applies to This article does not apply to This article is not tied to any specific product. Not all product versions are identified in this article.

Impact

High

Details

Third-party Component

CVEs

 More Information

MongoDB

CVE-2024-7553

See NVD link below for individual scores for each CVE. http://nvd.nist.gov/This hyperlink is taking you to a website outside of Dell Technologies.

 

Proprietary Code

CVEs

Description

CVSS Base Score

CVSS Vector String

CVE-2024-49595

Dell Wyse Management Suite, version WMS 4.4 and before, contain an Authentication Bypass by Capture-replay vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Denial of service.

7.6

 

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:LThis hyperlink is taking you to a website outside of Dell Technologies.

 

CVE-2024-49597

Dell Wyse Management Suite, versions WMS 4.4 and prior, contain an Improper Restriction of Excessive Authentication Attempts vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Protection mechanism bypass.

7.6

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:LThis hyperlink is taking you to a website outside of Dell Technologies.

CVE-2024-49596

Dell Wyse Management Suite, version WMS 4.4 and prior, contain a Missing Authorization vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Denial of service and arbitrary file deletion

5.9

CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:HThis hyperlink is taking you to a website outside of Dell Technologies.

Proprietary Code

CVEs

Description

CVSS Base Score

CVSS Vector String

CVE-2024-49595

Dell Wyse Management Suite, version WMS 4.4 and before, contain an Authentication Bypass by Capture-replay vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Denial of service.

7.6

 

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:LThis hyperlink is taking you to a website outside of Dell Technologies.

 

CVE-2024-49597

Dell Wyse Management Suite, versions WMS 4.4 and prior, contain an Improper Restriction of Excessive Authentication Attempts vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Protection mechanism bypass.

7.6

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:LThis hyperlink is taking you to a website outside of Dell Technologies.

CVE-2024-49596

Dell Wyse Management Suite, version WMS 4.4 and prior, contain a Missing Authorization vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Denial of service and arbitrary file deletion

5.9

CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:HThis hyperlink is taking you to a website outside of Dell Technologies.

Dell Technologies recommends all customers consider both the CVSS base score and any relevant temporal and environmental scores that may impact the potential severity associated with a particular security vulnerability.

Affected Products & Remediation

CVEs addressed

Product

Affected Versions

Remediated Versions

Release Date

Link

CVE-2024-7553, CVE-2024-49595, CVE-2024-49597, CVE-2024-49596

Dell Wyse Management Suite

Versions 4.4 and prior

 

Versions          

4.4.1 or later

11/25/2024

Dell Wyse Management Suite

CVE-2024-49596

Dell Wyse Management Suite Repository

Versions 4.4 and prior

 

Versions          

4.4.1 or later

11/25/2024

Dell Wyse Management Suite Repository

CVEs addressed

Product

Affected Versions

Remediated Versions

Release Date

Link

CVE-2024-7553, CVE-2024-49595, CVE-2024-49597, CVE-2024-49596

Dell Wyse Management Suite

Versions 4.4 and prior

 

Versions          

4.4.1 or later

11/25/2024

Dell Wyse Management Suite

CVE-2024-49596

Dell Wyse Management Suite Repository

Versions 4.4 and prior

 

Versions          

4.4.1 or later

11/25/2024

Dell Wyse Management Suite Repository

Workarounds & Mitigations

None

Revision History

Revision

Date

Description

1.0

2024-11-25

Initial Release

2.0 

2024-11-26

Updated for enhancements to presentation with no change in content.  

Acknowledgements

CVE-2024-49596: Dell Technologies would like to thank Ahmed Y. Elmogy for reporting this issue.

CVE-2024-49595: Dell Technologies would like to thank Harm Blankers, Jasper Westerman, Yanick de Pater of REQON B.V. for reporting this issue.

Related Information

Affected Products

Wyse Management Suite
Article Properties
Article Number: 000244453
Article Type: Dell Security Advisory
Last Modified: 26 Nov 2024
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.