PT-2021-11680 · Dell · Dell Wyse Management Suite
Khalid Latifi
·
Published
2021-01-04
·
Updated
2021-01-06
·
CVE-2020-29498
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
Dell Wyse Management Suite versions prior to 3.1
Description:
The issue allows a remote unauthenticated attacker to redirect application users to arbitrary web URLs by tricking victims into clicking on maliciously crafted links. This could be used to conduct phishing attacks, causing users to unknowingly visit malicious sites.
Recommendations:
For versions prior to 3.1, update to version 3.1 or later to resolve the issue. As a temporary workaround, consider restricting access to potentially vulnerable links and educating users about the risks of clicking on unsolicited or suspicious links.
Fix
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dell Wyse Management Suite