CVE-2022-46754

Wyse Management Suite 3.8 and below contain an improper access control vulnerability. A authenticated malicious admin user might access certain pro license features for which this admin is not authorized in order to configure user controlled external entities.
Configurations

Configuration 1 (hide)

cpe:2.3:a:dell:wyse_management_suite:*:*:*:*:*:*:*:*

History

21 Nov 2024, 07:31

Type Values Removed Values Added
References () https://www.dell.com/support/kbdoc/en-us/000206134/dsa-2022-329-dell-wyse-management-suite-security-update-for-multiple-vulnerabilities - Vendor Advisory () https://www.dell.com/support/kbdoc/en-us/000206134/dsa-2022-329-dell-wyse-management-suite-security-update-for-multiple-vulnerabilities - Vendor Advisory
CVSS v2 : unknown
v3 : 6.5
v2 : unknown
v3 : 8.7

07 Nov 2023, 03:55

Type Values Removed Values Added
Summary Wyse Management Suite 3.8 and below contain an improper access control vulnerability. A authenticated malicious admin user might access certain pro license features for which this admin is not authorized in order to configure user controlled external entities. Wyse Management Suite 3.8 and below contain an improper access control vulnerability. A authenticated malicious admin user might access certain pro license features for which this admin is not authorized in order to configure user controlled external entities.

Information

Published : 2023-02-11 01:23

Updated : 2024-11-21 07:31


NVD link : CVE-2022-46754

Mitre link : CVE-2022-46754

CVE.ORG link : CVE-2022-46754


JSON object : View

Products Affected

dell

  • wyse_management_suite
CWE
CWE-284

Improper Access Control

NVD-CWE-Other