PT-2021-11680 · Dell · Dell Wyse Management Suite

Khalid Latifi

·

Published

2021-01-04

·

Updated

2021-01-06

·

CVE-2020-29498

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Dell Wyse Management Suite versions prior to 3.1
Description: The issue allows a remote unauthenticated attacker to redirect application users to arbitrary web URLs by tricking victims into clicking on maliciously crafted links. This could be used to conduct phishing attacks, causing users to unknowingly visit malicious sites.
Recommendations: For versions prior to 3.1, update to version 3.1 or later to resolve the issue. As a temporary workaround, consider restricting access to potentially vulnerable links and educating users about the risks of clicking on unsolicited or suspicious links.

Fix

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-29498

Affected Products

Dell Wyse Management Suite