Impact
A file upload handler in Dell Wyse Management Suite does not validate the type of files that can be uploaded. An attacker who can reach the WMS application over the network can send a malicious file—such as a script or executable—to the server. The upload endpoint runs without authentication, and the uploaded content is executed with the privileges of the WMS service, allowing the attacker to run arbitrary commands and effectively take control of the underlying host.
Affected Systems
The vulnerability affects all Dell Wyse Management Suite installations with a version earlier than 2605.0.3.683. Systems running that release or newer are not impacted.
Risk and Exploitability
The CVSS base score of 8.6 reflects a high severity due to remote code execution without authentication. The EPSS score of less than 1% indicates that, while the vulnerability is technically exploitable, its current exploitation rate in the wild is very low. The vulnerability is not listed in CISA’s KEV catalog, and no widespread exploits have been reported, but the impact of a successful attack remains significant. The attack vector is inferred to be via a publicly accessible file‑upload endpoint on the WMS server.
OpenCVE Enrichment