Sensitive Data Exposure in Wyse Device Agent Affects Dell Products
CVE-2022-23158
6MEDIUM
Summary
The Wyse Device Agent is prone to a sensitive data exposure vulnerability that affects versions 14.6.1.4 and earlier. A local authenticated user with standard privileges can exploit this vulnerability to supply incorrect port information, thereby connecting to a valid WMS server. This exposure could lead to unauthorized access to sensitive information, highlighting the necessity for updating to the latest version to mitigate potential risks.
Affected Version(s)
Dell Wyse Device Agent < 14.6.2.13
References
CVSS V3.1
Score:
6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved