Description
Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain a Use of Hard-coded Credentials vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Unauthorized access.
Published: 2026-08-14
Score: 6.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Dell Wyse Management Suite (WMS) prior to version 2605.0.2 contains hard‑coded credentials that can be accessed by an attacker who has local, low‑privileged access. The vulnerability allows the attacker to bypass authentication and obtain unauthorized access to the management suite, enabling further privileged actions. This use of hard‑coded credentials is a direct breach of authentication controls and could lead to compromise of the management environment.

Affected Systems

Dell Wyse Management Suite versions earlier than 2605.0.2 are affected. The vulnerability applies to all installations of the suite that rely on the embedded hard‑coded credentials, regardless of other configuration settings.

Risk and Exploitability

The CVSS score of 6.3 indicates a medium severity impact. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting that it is not known to be actively exploited in the wild. An attacker must have local access, which typically requires physical or remote foothold, but with low privilege they may still exploit the hard‑coded credentials to gain unauthorized access.

Generated by OpenCVE AI on August 14, 2026 at 16:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Dell Wyse Management Suite update 2605.0.2 or later via the Dell security update documentation available at https://www.dell.com/support/kbdoc/en-us/000493271/dsa-2026-329-security-update-for-dell-wyse-management-suite-wms-for-multiple-vulnerabilities
  • Remove or modify any hard‑coded credentials used by WMS and implement proper authentication mechanisms
  • Ensure local user accounts follow least privilege principles and monitor for unauthorized access attempts

Generated by OpenCVE AI on August 14, 2026 at 16:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 14 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
Title Dell Wyse Management Suite Use of Hard‑coded Credentials Leading to Unauthorized Local Access

Fri, 14 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
Description Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain a Use of Hard-coded Credentials vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Unauthorized access.
Weaknesses CWE-798
References
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-08-14T15:28:06.599Z

Reserved: 2026-07-17T17:05:09.171Z

Link: CVE-2026-63702

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-14T16:16:58.800

Modified: 2026-08-14T16:16:58.800

Link: CVE-2026-63702

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-14T16:30:05Z

Weaknesses
  • CWE-798

    Use of Hard-coded Credentials