Executive brief
Dell Wyse Management Suite, a centralized solution for managing and configuring Dell thin clients, is vulnerable to a security flaw that could allow unauthorized access to data. An attacker with low-level user credentials could exploit this vulnerability to bypass security controls and view sensitive information or disrupt management operations. This could lead to the exposure of device configurations or administrative data across the corporate network.
Technical details
An SQL injection vulnerability (CWE-89) exists in Dell Wyse Management Suite (WMS) due to improper neutralization of special elements used in SQL commands. The flaw is reachable over the network and requires low-privileged authentication (PR:L) to exploit. Successful exploitation allows an attacker to execute arbitrary SQL queries against the backend database, potentially leading to the disclosure of sensitive information (Confidentiality: High) or causing service disruption (Availability: High). Dell has addressed this issue in WMS version 2605.
Affected products
- Dell Wyse Management Suite (WMS) Versions prior to 2605
Timeline
- 2026-06-01: patched: Remediated version 2605 released.
- 2026-06-16: disclosed: Initial advisory release by Dell.
- 2026-06-22: advisory: NVD publication and advisory update.