DSA-2024-440: Security Update for Dell Wyse Management Suite (WMS) for Multiple Vulnerabilities
Summary: Dell Wyse Management Suite (WMS) remediation is available for multiple vulnerabilities that may be exploited by malicious users to compromise the affected system.
Impact
High
Details
| Third-party Component |
CVEs |
More Information |
| MongoDB |
CVE-2024-7553 |
See NVD link below for individual scores for each CVE. http://nvd.nist.gov/
|
| Proprietary Code CVEs |
Description |
CVSS Base Score |
CVSS Vector String |
| CVE-2024-49595 |
Dell Wyse Management Suite, version WMS 4.4 and before, contain an Authentication Bypass by Capture-replay vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Denial of service. |
7.6
|
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L
|
| CVE-2024-49597 |
Dell Wyse Management Suite, versions WMS 4.4 and prior, contain an Improper Restriction of Excessive Authentication Attempts vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Protection mechanism bypass. |
7.6 |
|
| CVE-2024-49596 |
Dell Wyse Management Suite, version WMS 4.4 and prior, contain a Missing Authorization vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Denial of service and arbitrary file deletion |
5.9 |
| Proprietary Code CVEs |
Description |
CVSS Base Score |
CVSS Vector String |
| CVE-2024-49595 |
Dell Wyse Management Suite, version WMS 4.4 and before, contain an Authentication Bypass by Capture-replay vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Denial of service. |
7.6
|
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L
|
| CVE-2024-49597 |
Dell Wyse Management Suite, versions WMS 4.4 and prior, contain an Improper Restriction of Excessive Authentication Attempts vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Protection mechanism bypass. |
7.6 |
|
| CVE-2024-49596 |
Dell Wyse Management Suite, version WMS 4.4 and prior, contain a Missing Authorization vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Denial of service and arbitrary file deletion |
5.9 |
Affected Products & Remediation
| CVEs addressed |
Product |
Affected Versions |
Remediated Versions |
Release Date |
Link |
| CVE-2024-7553, CVE-2024-49595, CVE-2024-49597, CVE-2024-49596 |
Dell Wyse Management Suite |
Versions 4.4 and prior
|
Versions 4.4.1 or later |
11/25/2024 |
|
| CVE-2024-49596 |
Dell Wyse Management Suite Repository |
Versions 4.4 and prior
|
Versions 4.4.1 or later |
11/25/2024 |
| CVEs addressed |
Product |
Affected Versions |
Remediated Versions |
Release Date |
Link |
| CVE-2024-7553, CVE-2024-49595, CVE-2024-49597, CVE-2024-49596 |
Dell Wyse Management Suite |
Versions 4.4 and prior
|
Versions 4.4.1 or later |
11/25/2024 |
|
| CVE-2024-49596 |
Dell Wyse Management Suite Repository |
Versions 4.4 and prior
|
Versions 4.4.1 or later |
11/25/2024 |
Workarounds & Mitigations
None
Revision History
|
Revision |
Date |
Description |
|
1.0 |
2024-11-25 |
Initial Release |
|
2.0 |
2024-11-26 |
Updated for enhancements to presentation with no change in content. |
Acknowledgements
CVE-2024-49596: Dell Technologies would like to thank Ahmed Y. Elmogy for reporting this issue.
CVE-2024-49595: Dell Technologies would like to thank Harm Blankers, Jasper Westerman, Yanick de Pater of REQON B.V. for reporting this issue.