Executive brief
Dell Wyse Management Suite, a centralized solution for managing Dell thin clients, is vulnerable to a security flaw that could allow an attacker to gain unauthorized access to the system. By exploiting this vulnerability, a user with low-level access could manipulate the underlying database to view, modify, or delete sensitive management data. This could lead to a full compromise of the management console and the devices it controls.
Technical details
An SQL injection vulnerability (CWE-89) exists in Dell Wyse Management Suite (WMS) due to improper neutralization of special elements used in SQL commands. The flaw allows a remote attacker with low-privileged credentials to inject malicious SQL queries into the application's database layer. Successful exploitation can lead to unauthorized access, data exfiltration, and modification of database records, potentially resulting in a complete loss of confidentiality, integrity, and availability. The issue is resolved in WMS version 2605.
Affected products
- Dell Wyse Management Suite (WMS) Versions prior to 2605
Timeline
- 2026-06-01: patched: Remediated version 2605 released
- 2026-06-16: disclosed: Initial advisory release by Dell
- 2026-06-22: advisory: NVD publication and advisory revision 2.0