PT-2023-23816 · Dell · Wyse Management Suite
CVE-2023-32482
·
Publicado
2023-07-20
·
Atualizado
2023-07-26
CVSS v3.1
4.9
Média
| Vetor | AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Wyse Management Suite versions prior to 4.0
Description
The issue is related to improper authorization, allowing an authenticated malicious user with privileged access to push policies to unauthorized tenant groups.
Recommendations
For Wyse Management Suite versions prior to 4.0, update to version 4.0 or later to resolve the issue. As a temporary workaround, consider restricting access to policy management features to minimize the risk of unauthorized policy pushes.
Correção
Incorrect Authorization
Improper Authorization
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Wyse Management Suite