Impact
Dell Wyse Management Suite versions prior to 2605.0.2 contain an unrestricted file upload flaw that allows a high‑privileged remote attacker to upload files of dangerous types. The vulnerability falls under CWE‑434 and can lead to direct remote code execution on the affected system if the attacker succeeds in uploading a malicious payload. The impact is broad, potentially affecting system confidentiality, integrity, and availability as the attacker gains the ability to run arbitrary code on the server.
Affected Systems
The affected product is Dell Wyse Management Suite (WMS) for all versions earlier than 2605.0.2.
Risk and Exploitability
The CVSS score is 7.2, indicating a high severity. No EPSS score is published, so the likelihood of exploitation is currently unknown. The vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be remote, requiring high‑privileged access, as stated in the advisory. If an attacker is able to reach the upload functionality, the flaw can be abused to achieve remote code execution.
OpenCVE Enrichment