Impact
Dell Wyse Management Suite (WMS) prior to version 2605.0.2 contains hard‑coded credentials that can be accessed by an attacker who has local, low‑privileged access. The vulnerability allows the attacker to bypass authentication and obtain unauthorized access to the management suite, enabling further privileged actions. This use of hard‑coded credentials is a direct breach of authentication controls and could lead to compromise of the management environment.
Affected Systems
Dell Wyse Management Suite versions earlier than 2605.0.2 are affected. The vulnerability applies to all installations of the suite that rely on the embedded hard‑coded credentials, regardless of other configuration settings.
Risk and Exploitability
The CVSS score of 6.3 indicates a medium severity impact. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting that it is not known to be actively exploited in the wild. An attacker must have local access, which typically requires physical or remote foothold, but with low privilege they may still exploit the hard‑coded credentials to gain unauthorized access.
OpenCVE Enrichment