Impact
Dell Wyse Management Suite versions earlier than 2605.0.3.683 expose an Unrestricted Upload of File with Dangerous Type flaw. An unauthenticated attacker who can reach the management interface can upload a malicious file that the system will execute without further validation, resulting in Remote Code Execution. This weakness is classified as CWE-434 and provides a direct, user‑agnostic code‑execution vector.
Affected Systems
The affected product is Dell Wyse Management Suite, specifically the WMS management console and the components that process file uploads. All installations running a version older than 2605.0.3.683 are vulnerable.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.6, indicating high severity. The EPSS score of less than 1% shows a very low but non‑zero probability of exploitation in the wild, yet the lack of a KEV listing does not mitigate the risk. Attackers only need remote unauthenticated access to the WMS management interface, a common scenario for exposed management consoles, to exploit the flaw and achieve remote code execution.
OpenCVE Enrichment