Vulnerabilities > Dell > Wyse Management Suite > 1.4

DATE CVE VULNERABILITY TITLE RISK
2022-06-24 CVE-2022-29097 Path Traversal vulnerability in Dell Wyse Management Suite
Dell WMS 3.6.1 and below contains a Path Traversal vulnerability in Device API.
network
low complexity
dell CWE-22
4.0
2021-12-21 CVE-2021-36336 Deserialization of Untrusted Data vulnerability in Dell Wyse Management Suite
Wyse Management Suite 3.3.1 and below versions contain a deserialization vulnerability that could allow an unauthenticated attacker to execute code on the affected system.
network
low complexity
dell CWE-502
7.5
2021-12-21 CVE-2021-36337 Inadequate Encryption Strength vulnerability in Dell Wyse Management Suite
Dell Wyse Management Suite version 3.3.1 and prior support insecure Transport Security Protocols TLS 1.0 and TLS 1.1 which are susceptible to Man-In-The-Middle attacks thereby compromising Confidentiality and Integrity of data.
network
dell CWE-326
5.8
2021-07-15 CVE-2021-21586 Path Traversal vulnerability in Dell Wyse Management Suite
Wyse Management Suite versions 3.2 and earlier contain an absolute path traversal vulnerability.
network
low complexity
dell CWE-22
6.8
2021-07-15 CVE-2021-21587 Information Exposure vulnerability in Dell Wyse Management Suite
Dell Wyse Management Suite versions 3.2 and earlier contain a full path disclosure vulnerability.
local
low complexity
dell CWE-200
2.1
2021-04-02 CVE-2021-21533 Improper Input Validation vulnerability in Dell Wyse Management Suite
Wyse Management Suite versions up to 3.2 contains a vulnerability wherein a malicious authenticated user can cause a denial of service in the job status retrieval page, also affecting other users that would have normally access to the same subset of job details
network
low complexity
dell CWE-20
4.0
2021-01-04 CVE-2020-29498 Open Redirect vulnerability in Dell Wyse Management Suite
Dell Wyse Management Suite versions prior to 3.1 contain an open redirect vulnerability.
network
dell CWE-601
5.8
2021-01-04 CVE-2020-29497 Cross-site Scripting vulnerability in Dell Wyse Management Suite
Dell Wyse Management Suite versions prior to 3.1 contain a stored cross-site scripting vulnerability.
network
dell CWE-79
3.5
2021-01-04 CVE-2020-29496 Cross-site Scripting vulnerability in Dell Wyse Management Suite
Dell Wyse Management Suite versions prior to 3.1 contain a stored cross-site scripting vulnerability.
network
dell CWE-79
3.5
2020-03-13 CVE-2019-3770 Cross-site Scripting vulnerability in Dell Wyse Management Suite
Dell Wyse Management Suite versions prior to 1.4.1 contain a stored cross-site scripting vulnerability when unregistering a device.
network
dell CWE-79
3.5