Executive brief
Dell Wyse Management Suite, a platform used to manage and configure thin client devices, is vulnerable to a security flaw that could allow an attacker to execute unauthorized commands. An attacker with high-level administrative privileges could bypass folder restrictions to access or modify sensitive system files. This could lead to a complete takeover of the management server, potentially impacting the security and availability of all managed devices.
Technical details
A path traversal vulnerability (CWE-22) exists in Dell Wyse Management Suite (WMS) due to improper limitation of pathnames to restricted directories. A remote attacker with high privileges can exploit this flaw by submitting specially crafted input to access files outside of the intended directory. Successful exploitation can lead to Remote Code Execution (RCE) on the underlying operating system. The vulnerability is addressed in version 5.5 HF1 and later. Authentication is required (High privileges), but no user interaction is needed for exploitation.
Affected products
- Dell Wyse Management Suite (WMS) Versions prior to 5.5 HF1
Timeline
- 2026-05-08: patched: Remediated version 5.5 HF1 released
- 2026-06-16: advisory: Initial Dell security advisory (DSA-2026-225) published
- 2026-06-25: disclosed: CVE published to NVD