Sensitive Data Exposure in Wyse Device Agent Affects Dell Products
CVE-2022-23158

6MEDIUM

Key Information:

Vendor
Dell
Vendor
CVE Published:
1 April 2022

Summary

The Wyse Device Agent is prone to a sensitive data exposure vulnerability that affects versions 14.6.1.4 and earlier. A local authenticated user with standard privileges can exploit this vulnerability to supply incorrect port information, thereby connecting to a valid WMS server. This exposure could lead to unauthorized access to sensitive information, highlighting the necessity for updating to the latest version to mitigate potential risks.

Affected Version(s)

Dell Wyse Device Agent < 14.6.2.13

References

CVSS V3.1

Score:
6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.