Improper Authentication Vulnerability in Wyse Device Agent by Dell
CVE-2022-23156

6MEDIUM

Key Information:

Vendor
Dell
Vendor
CVE Published:
1 April 2022

Summary

The Wyse Device Agent prior to version 14.6.1.5 is susceptible to an Improper Authentication vulnerability. This flaw allows a malicious actor to exploit the system by manipulating input data, enabling unauthorized access to the WMS server. Organizations using the affected versions should take immediate action to apply necessary updates and mitigate potential risks from this vulnerability.

Affected Version(s)

Dell Wyse Device Agent < 14.6.2.13

References

CVSS V3.1

Score:
6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.