Description
Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain a Missing Cryptographic Step vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Information tampering.
Published: 2026-09-15
Score: 8 High
EPSS: < 1% Very Low
KEV: No
Impact: Information tampering
Action: Apply Patch
AI Analysis

Impact

Dell Wyse Management Suite versions prior to 2605.0.3.683 contain a missing cryptographic step that corresponds to CWE‑325 Missing Cryptographic Step. This flaw allows an attacker who has high‑level privileges and remote access to tamper with cryptographically protected data, potentially modifying configuration or management information across managed desktops and servers.

Affected Systems

Dell Wyse Management Suite (WMS) for all deployments of versions earlier than 2605.0.3.683. The affected product is any WMS installation hosted within an organization’s infrastructure.

Risk and Exploitability

The CVSS score of 8.0 characterizes the vulnerability as high severity, indicating that an attacker with the required privileges could cause significant integrity damage. The EPSS score is < 1%, indicating a very low exploitation probability. The flaw is listed in the CWE‑325 category, revealing that it stems from a missing cryptographic step. The vulnerability is not listed in the CISA KEV catalog, suggesting that no public exploitation has been observed. Attackers would still need to compromise a privileged account with remote access to the WMS server; once accessed, they could manipulate secure data streams or files to achieve tampering.

Generated by OpenCVE AI on September 20, 2026 at 14:35 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply Dell DSA‑2026‑387 security update to upgrade WMS to 2605.0.3.683 or later.
  • Enable cryptographic integrity checks in the WMS configuration to prevent future tampering.
  • Monitor system logs for unauthorized modifications.

Generated by OpenCVE AI on September 20, 2026 at 14:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:dell:wyse_management_suite:*:*:*:*:*:*:*:*

Sun, 20 Sep 2026 15:00:00 +0000

Type Values Removed Values Added
Title Missing Cryptographic Step Allows Remote Tampering in Dell Wyse Management Suite

Thu, 17 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Title Missing Cryptographic Step in Dell Wyse Management Suite Enables Information Tampering

Wed, 16 Sep 2026 02:45:00 +0000

Type Values Removed Values Added
Title Missing Cryptographic Step in Dell Wyse Management Suite Enables Information Tampering

Tue, 15 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell wyse Management Suite
Vendors & Products Dell
Dell wyse Management Suite

Tue, 15 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
Description Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain a Missing Cryptographic Step vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Information tampering.
Weaknesses CWE-325
References
Metrics cvssV3_1

{'score': 8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Dell Wyse Management Suite
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-16T03:56:57.897Z

Reserved: 2026-08-26T17:05:27.563Z

Link: CVE-2026-81235

cve-icon Vulnrichment

Updated: 2026-09-15T19:01:44.383Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T18:19:24.023

Modified: 2026-09-21T17:32:01.537

Link: CVE-2026-81235

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T14:45:06Z

Weaknesses
  • CWE-325

    Missing Cryptographic Step