Impact
Dell Wyse Management Suite versions prior to 2605.0.3.683 contain a missing cryptographic step that corresponds to CWE‑325 Missing Cryptographic Step. This flaw allows an attacker who has high‑level privileges and remote access to tamper with cryptographically protected data, potentially modifying configuration or management information across managed desktops and servers.
Affected Systems
Dell Wyse Management Suite (WMS) for all deployments of versions earlier than 2605.0.3.683. The affected product is any WMS installation hosted within an organization’s infrastructure.
Risk and Exploitability
The CVSS score of 8.0 characterizes the vulnerability as high severity, indicating that an attacker with the required privileges could cause significant integrity damage. The EPSS score is < 1%, indicating a very low exploitation probability. The flaw is listed in the CWE‑325 category, revealing that it stems from a missing cryptographic step. The vulnerability is not listed in the CISA KEV catalog, suggesting that no public exploitation has been observed. Attackers would still need to compromise a privileged account with remote access to the WMS server; once accessed, they could manipulate secure data streams or files to achieve tampering.
OpenCVE Enrichment