Impact
The vulnerability is an unrestricted upload of files with dangerous types in Dell Wyse Management Suite, exposing the system to remote code execution. An unauthenticated attacker who can access the management interface can upload a malicious file that the server processes or executes, potentially giving the attacker full control of the host. This flaw is a classic file‑upload weakness that bypasses type validation and is the root cause behind the remote execution risk.
Affected Systems
Dell Wyse Management Suite versions prior to 2605.0.3.683 are affected. The flaw operates in any deployment of the product, independent of the underlying operating system, and impacts all instances that have not applied the 2605.0.3.683 update or later.
Risk and Exploitability
The likelihood of exploitation is reported to be very low, with an EPSS score of <1%, but the CVSS score of 8.6 classifies it as high severity and indicates a potentially severe impact if any attacker succeeds. The attack surface is broad because the vulnerability is reachable through any unauthenticated remote connection to the management interface. The vulnerability does not require privileged access or local code, and the lack of authentication into the upload feature creates a very accessible vector. No public exploit has been disclosed in the advisory; this statement is inferred based on the lack of mention in the documentation and the low exploitation probability reflected in the EPSS.
OpenCVE Enrichment