Path Traversal Vulnerability in Wyse Management Suite by Dell
CVE-2022-34365
6.5MEDIUM
Summary
The Wyse Management Suite version 3.7 by Dell is impacted by a path traversal vulnerability that could allow attackers to gain unauthorized read access to sensitive files on the server's filesystem. By exploiting this flaw in the Device API, an attacker may leverage the privileges of the running web application, leading to potential data exposure and compromise. Security measures and updates are essential to mitigate this risk and protect sensitive information.
Affected Version(s)
Wyse Management Suite < 3.8
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved