Impact
The vulnerability is an Unrestricted Upload of Dangerous Type that allows an attacker with high privileged remote access to upload a malicious file and have it executed by the server, resulting in Remote Code Execution. This flaw grants the attacker the same privileges as the application, enabling full compromise of the affected system. The weakness is categorized as CWE-434.
Affected Systems
Dell Wyse Management Suite (Dell:Wyse Management Suite), versions prior to 2605.0.2, are affected. These systems are typically deployed in enterprise environments for device management and are listed as the sole impacted vendor and product. No other vendors or versions are cited.
Risk and Exploitability
The CVSS score of 7.2 reflects a medium to high severity. EPSS is not available, so the exploitation probability is unknown, and the vulnerability is not listed in CISA's KEV catalog. The attack requires remote access with high privileges, such as an administrator, and can be performed via the web interface that accepts file uploads.
OpenCVE Enrichment