Home/Product/dell wyse management suite
Product

dell wyse management suite

52 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-23859
< 5.5
Dell Wyse Management Suite, versions prior to WMS 5.5, contain a Client-Side Enforcement of Server-Side Security vulnerability. A
2.7LOW
CVE-2026-23858
< 5.5
Dell Wyse Management Suite, versions prior to WMS 5.5, contain an Improper Neutralization of Input During Web Page Generation ('Cr
5.4MEDIUM
CVE-2026-22766
< 5.5
Dell Wyse Management Suite, versions prior to WMS 5.5, contain an Unrestricted Upload of File with Dangerous Type vulnerability. A
7.2HIGH
CVE-2026-22765
< 5.5
Dell Wyse Management Suite, versions prior to WMS 5.5, contain a Missing Authorization vulnerability. A low privileged attacker wi
8.8HIGH
CVE-2025-36580
< 5.2
Dell Wyse Management Suite, versions prior to WMS 5.2, contain an Improper Neutralization of Input During Web Page Generation ('Cr
6.1MEDIUM
CVE-2025-36578
< 5.2
Dell Wyse Management Suite, versions prior to WMS 5.2, contain an Incorrect Authorization vulnerability. A low privileged attacker
6.8MEDIUM
CVE-2025-36577
< 5.2
Dell Wyse Management Suite, versions prior to WMS 5.2, contain an Improper Neutralization of Input During Web Page Generation ('Cr
6.1MEDIUM
CVE-2025-36576
< 5.2
Dell Wyse Management Suite, versions prior to WMS 5.2, contain a Cross-Site Request Forgery (CSRF) vulnerability. A high privilege
2.7LOW
CVE-2025-36575
< 5.2
Dell Wyse Management Suite, versions prior to WMS 5.2, contain an Exposure of Sensitive Information Through Data Queries vulnerabi
7.5HIGH
CVE-2025-36574
< 5.2
Dell Wyse Management Suite, versions prior to WMS 5.2, contain an Absolute Path Traversal vulnerability. An unauthenticated attack
8.2HIGH
CVE-2025-27695
< 5.1
Dell Wyse Management Suite, versions prior to WMS 5.1 contain an Authentication Bypass by Spoofing vulnerability. A high privilege
4.9MEDIUM
CVE-2025-29982
< 5.1
Dell Wyse Management Suite, versions prior to WMS 5.1, contains an Insecure Inherited Permissions vulnerability. A low privileged
6.8MEDIUM
CVE-2025-29981
< 5.1
Dell Wyse Management Suite, versions prior to WMS 5.1, contains an Exposure of Sensitive Information Through Data Queries vulnerab
7.5HIGH
CVE-2025-27694
< 5.1
Dell Wyse Management Suite, versions prior to WMS 5.1, contains an Insufficient Resource Pool vulnerability. An unauthenticated a
5.3MEDIUM
CVE-2025-27693
< 5.1
Dell Wyse Management Suite, versions prior to WMS 5.1, contains an Improper Neutralization of Input During Web Page Generation ('C
4.9MEDIUM
CVE-2025-27692
< 5.1
Dell Wyse Management Suite, versions prior to WMS 5.1, contains an Unrestricted Upload of File with Dangerous Type vulnerability.
4.7MEDIUM
CVE-2024-49597
<= 4.4
Dell Wyse Management Suite, versions WMS 4.4 and prior, contain an Improper Restriction of Excessive Authentication Attempts vulne
7.6HIGH
CVE-2024-49596
<= 4.4
Dell Wyse Management Suite, version WMS 4.4 and prior, contain a Missing Authorization vulnerability. A high privileged attacker w
5.9MEDIUM
CVE-2024-49595
<= 4.4
Dell Wyse Management Suite, version WMS 4.4 and before, contain an Authentication Bypass by Capture-replay vulnerability. A high p
7.6HIGH
CVE-2023-32483
< 4.0
Wyse Management Suite versions prior to 4.0 contain a sensitive information disclosure vulnerability. An authenticated malicious u
4.4MEDIUM
CVE-2023-32482
< 4.0
Wyse Management Suite versions prior to 4.0 contain an improper authorization vulnerability. An authenticated malicious user with
4.9MEDIUM
CVE-2023-32481
< 4.0
Wyse Management Suite versions prior to 4.0 contain a denial-of-service vulnerability. An authenticated malicious user can flood t
4.9MEDIUM
CVE-2022-46755
<= 3.8.0
Wyse Management Suite 3.8 and below contain an improper access control vulnerability. A authenticated malicious admin user can edi
4.9MEDIUM
CVE-2022-46754
<= 3.8.0
Wyse Management Suite 3.8 and below contain an improper access control vulnerability. A authenticated malicious admin user might a
8.7HIGH
CVE-2022-46678
<= 3.8.0
Wyse Management Suite 3.8 and below contain an improper access control vulnerability. A authenticated malicious admin user can e
4.9MEDIUM
CVE-2022-46677
<= 3.8.0
Wyse Management Suite 3.8 and below contain an improper access control vulnerability with which an custom group admin can create a
6.8MEDIUM
CVE-2022-46676
<= 3.8.0
Wyse Management Suite 3.8 and below contain an improper access control vulnerability. A malicious admin user can disable or delete
4.9MEDIUM
CVE-2022-46675
<= 3.8
Wyse Management Suite Repository 3.8 and below contain an information disclosure vulnerability. A unauthenticated attacker could p
5.3MEDIUM
CVE-2022-34365
< 3.8.0
WMS 3.7 contains a Path Traversal Vulnerability in Device API. An attacker could potentially exploit this vulnerability, to gain u
6.5MEDIUM
CVE-2022-33931
< 3.8.0
Dell Wyse Management Suite 3.6.1 and below contains an Improper Access control vulnerability in UI. An attacker with no access to
6.3MEDIUM
CVE-2022-33930
< 3.8.0
Dell Wyse Management Suite 3.6.1 and below contains Information Disclosure in Devices error pages. An attacker could potentially e
4.3MEDIUM
CVE-2022-33929
< 3.8.0
Dell Wyse Management Suite 3.6.1 and below contains a Reflected Cross-Site Scripting Vulnerability in EndUserSummary page. An auth
6.1MEDIUM
CVE-2022-33928
< 3.8.0
Dell Wyse Management Suite 3.6.1 and below contains an Plain-text Password Storage Vulnerability in UI. An attacker with low privi
6.4MEDIUM
CVE-2022-33927
< 3.8.0
Dell Wyse Management Suite 3.6.1 and below contains a Session Fixation vulnerability. A unauthenticated attacker could exploit thi
5.4MEDIUM
CVE-2022-33926
< 3.8.0
Dell Wyse Management Suite 3.6.1 and below contains an improper access control vulnerability. A remote malicious user could exploi
7.1HIGH
CVE-2022-33925
< 3.8.0
Dell Wyse Management Suite 3.6.1 and below contains an Improper Access control vulnerability in UI. An remote authenticated attack
6.5MEDIUM
CVE-2022-33924
< 3.8.0
Dell Wyse Management Suite 3.6.1 and below contains an Improper Access control vulnerability with which an attacker with no access
4.3MEDIUM
CVE-2022-29090
< 3.8.0
Dell Wyse Management Suite 3.6.1 and below contains a Sensitive Data Exposure vulnerability. A low privileged malicious user could
8.5HIGH
CVE-2022-29097
<= 3.6.1
Dell WMS 3.6.1 and below contains a Path Traversal vulnerability in Device API. A remote attacker could potentially exploit this v
4.9MEDIUM
CVE-2022-29096
<= 3.6.1
Dell Wyse Management Suite 3.6.1 and below contains a Reflected Cross-Site Scripting Vulnerability in saveGroupConfigurations page
6.1MEDIUM
CVE-2022-23155
>= 2.0 and <= 3.5.2
Dell Wyse Management Suite versions 2.0 through 3.5.2 contain an unrestricted file upload vulnerability. A malicious user with adm
7.2HIGH
CVE-2021-36337
<= 3.3.1
Dell Wyse Management Suite version 3.3.1 and prior support insecure Transport Security Protocols TLS 1.0 and TLS 1.1 which are sus
6.5MEDIUM
CVE-2021-36336
<= 3.3.1
Wyse Management Suite 3.3.1 and below versions contain a deserialization vulnerability that could allow an unauthenticated attacke
9.8CRITICAL
CVE-2021-21587
<= 3.2
Dell Wyse Management Suite versions 3.2 and earlier contain a full path disclosure vulnerability. A local unauthenticated attacker
5.3MEDIUM
CVE-2021-21586
<= 3.2
Wyse Management Suite versions 3.2 and earlier contain an absolute path traversal vulnerability. A remote authenticated malicious
8.1HIGH
CVE-2021-21533
< 3.2
Wyse Management Suite versions up to 3.2 contains a vulnerability wherein a malicious authenticated user can cause a denial of ser
4.3MEDIUM
CVE-2020-29498
< 3.1
Dell Wyse Management Suite versions prior to 3.1 contain an open redirect vulnerability. A remote unauthenticated attacker could p
6.1MEDIUM
CVE-2020-29497
< 3.1
Dell Wyse Management Suite versions prior to 3.1 contain a stored cross-site scripting vulnerability. A remote authenticated malic
5.4MEDIUM
CVE-2020-29496
< 3.1
Dell Wyse Management Suite versions prior to 3.1 contain a stored cross-site scripting vulnerability. A remote authenticated malic
4.8MEDIUM
CVE-2019-3770
< 1.4.1
Dell Wyse Management Suite versions prior to 1.4.1 contain a stored cross-site scripting vulnerability when unregistering a device
6.4MEDIUM
CVE-2019-3769
< 1.4.1
Dell Wyse Management Suite versions prior to 1.4.1 contain a stored cross-site scripting vulnerability. A remote authenticated mal
6.4MEDIUM
CVE-2018-11063
<= 1.1
Dell WMS versions 1.1 and prior are impacted by multiple unquoted service path vulnerabilities. Affected software installs multipl
7.8HIGH
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin