Impact
The Dell Wyse Management Suite before version 2605.0.3.683 suffers a missing authentication flaw in a critical function. An attacker who can reach the system remotely and who does not need to be authenticated can potentially trigger this function, resulting in unauthorized access to the management suite. The vulnerability is catalogued as CWE-306.
Affected Systems
Affected systems are Dell Wyse Management Suite installations whose version is older than 2605.0.3.683. The vulnerability applies to all builds of the suite released before that point. Administrators should verify that they are running a supported version of the product.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity. The EPSS score of < 1% indicates a very low but non-zero probability of exploitation, and the flaw is not listed in KEV, meaning no publicly known exploits are reported. Nevertheless, the lack of authentication gives an unauthenticated attacker remote access, a straightforward attack vector. The risk is high for any environment exposing the suite to remote connections. Administrators should therefore apply the latest security patch as soon as possible.
OpenCVE Enrichment