DSA-2022-030: Dell Wyse Management Suite Security Update for Multiple Vulnerabilities
Samenvatting: Dell Wyse Management Suite (WMS) contains remediation for multiple security vulnerabilities that may be exploited by malicious users to compromise the affected system.
Dit artikel is van toepassing op
Dit artikel is niet van toepassing op
Dit artikel is niet gebonden aan een specifiek product.
Niet alle productversies worden in dit artikel vermeld.
Impact
High
Gegevens
| Proprietary Code CVEs | Description | CVSS Base Score | CVSS Vector String |
| CVE-2022-23155 | Dell Wyse Management Suite versions 2.0 through 3.5.2 contain an unrestricted file upload vulnerability. A malicious user with admin privileges may potentially exploit this vulnerability in order to execute arbitrary code on the system. | 7.2 | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
| Third-party Component | CVEs | More information |
| Apache Log4j | CVE-2021-44832 | See NVD (http://nvd.nist.gov/) for individual scores for each CVE |
| Proprietary Code CVEs | Description | CVSS Base Score | CVSS Vector String |
| CVE-2022-23155 | Dell Wyse Management Suite versions 2.0 through 3.5.2 contain an unrestricted file upload vulnerability. A malicious user with admin privileges may potentially exploit this vulnerability in order to execute arbitrary code on the system. | 7.2 | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
| Third-party Component | CVEs | More information |
| Apache Log4j | CVE-2021-44832 | See NVD (http://nvd.nist.gov/) for individual scores for each CVE |
Getroffen producten en herstel
| Product | Affected Versions | Updated Versions | Link to Update |
| Dell Wyse Management Suite | 2.0 to 3.5.2 | 3.6 | Dell Wyse Management Suite |
| Product | Affected Versions | Updated Versions | Link to Update |
| Dell Wyse Management Suite | 2.0 to 3.5.2 | 3.6 | Dell Wyse Management Suite |
Revisiegeschiedenis
| Revision | Date | Description |
| 1.0 | 2022-02-17 | Initial Release |
Bevestigingen
CVE-2022-23155: Dell Technologies would like to thank bugbounty2k20 for reporting this issue.
Verwante informatie
Juridische verklaring van afstand
Getroffen producten
Product Security Information, Wyse Management SuiteArtikeleigenschappen
Artikelnummer: 000195918
Artikeltype: Dell Security Advisory
Laatst aangepast: 17 feb. 2022
Vind antwoorden op uw vragen via andere Dell gebruikers
Support Services
Controleer of uw apparaat wordt gedekt door Support Services.