Session Fixation Vulnerability in Dell Wyse Management Suite
CVE-2022-33927

5.4MEDIUM

Key Information:

Vendor
Dell
Vendor
CVE Published:
10 August 2022

Summary

The Dell Wyse Management Suite 3.6.1 and earlier versions are susceptible to a session fixation vulnerability. This allows unauthenticated attackers to exploit scenarios where a user has multiple active sessions, potentially enabling the hijacking of a user's session. Proper session management mechanisms should be implemented to mitigate this risk.

Affected Version(s)

Wyse Management Suite < 3.7

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.