Cross-Site Scripting Vulnerability in Dell Wyse Management Suite
CVE-2025-36577

6.1MEDIUM

Key Information:

Vendor

Dell

Vendor
CVE Published:
10 June 2025

What is CVE-2025-36577?

Dell Wyse Management Suite has a vulnerability that allows for improper neutralization of input during web page generation, resulting in a Cross-Site Scripting (XSS) condition. High privileged attackers with remote access could exploit this weakness to perform script injection, potentially compromising sensitive information and functionality. It is crucial for users of affected versions to upgrade to version 5.2 or later to mitigate risks associated with this vulnerability.

Affected Version(s)

Wyse Management Suite < 5.2

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.