Description
Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Unrestricted Upload of File with Dangerous Type vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.
Published: 2026-09-15
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

Dell Wyse Management Suite versions earlier than 2605.0.3.683 expose an Unrestricted Upload of File with Dangerous Type flaw. An unauthenticated attacker who can reach the management interface can upload a malicious file that the system will execute without further validation, resulting in Remote Code Execution. This weakness is classified as CWE-434 and provides a direct, user‑agnostic code‑execution vector.

Affected Systems

The affected product is Dell Wyse Management Suite, specifically the WMS management console and the components that process file uploads. All installations running a version older than 2605.0.3.683 are vulnerable.

Risk and Exploitability

The vulnerability carries a CVSS score of 8.6, indicating high severity. The EPSS score of less than 1% shows a very low but non‑zero probability of exploitation in the wild, yet the lack of a KEV listing does not mitigate the risk. Attackers only need remote unauthenticated access to the WMS management interface, a common scenario for exposed management consoles, to exploit the flaw and achieve remote code execution.

Generated by OpenCVE AI on September 20, 2026 at 14:38 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the Dell Security Advisory to upgrade to version 2605.0.3.683 or newer, which closes the unrestricted upload flaw.
  • Limit access to the WMS management console to trusted IP ranges or VPN endpoints using firewall rules to reduce exposure to unauthenticated remote users.
  • If the patch cannot be applied immediately, disable the file‑upload functionality or block the upload endpoints via configuration to prevent malicious files from being accepted until the system is patched.

Generated by OpenCVE AI on September 20, 2026 at 14:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:dell:wyse_management_suite:*:*:*:*:*:*:*:*

Sun, 20 Sep 2026 15:00:00 +0000

Type Values Removed Values Added
Title Unrestricted File Upload Vulnerability in Dell Wyse Management Suite Leading to Remote Code Execution

Fri, 18 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 12:00:00 +0000

Type Values Removed Values Added
Title Unrestricted File Upload in Dell Wyse Management Suite Enables Remote Execution

Wed, 16 Sep 2026 01:15:00 +0000

Type Values Removed Values Added
Title Unrestricted File Upload in Dell Wyse Management Suite Enables Remote Execution

Tue, 15 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Dell
Dell wyse Management Suite
Vendors & Products Dell
Dell wyse Management Suite
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
Description Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain an Unrestricted Upload of File with Dangerous Type vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.
Weaknesses CWE-434
References
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L'}


Subscriptions

Dell Wyse Management Suite
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2026-09-17T11:57:47.561Z

Reserved: 2026-08-26T17:05:27.564Z

Link: CVE-2026-81240

cve-icon Vulnrichment

Updated: 2026-09-15T18:38:45.438Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T18:19:24.630

Modified: 2026-09-21T17:31:15.503

Link: CVE-2026-81240

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T14:45:06Z

Weaknesses
  • CWE-434

    Unrestricted Upload of File with Dangerous Type