PT-2023-14986 · Dell · Wyse Management Suite

Published

2023-02-10

·

Updated

2023-02-21

·

CVE-2022-46676

CVSS v3.1

4.9

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Wyse Management Suite versions 3.8 and below
Description The issue concerns improper access control, allowing a malicious admin user to disable or delete users under administration and unassigned admins for which the group admin is not authorized.
Recommendations For Wyse Management Suite versions 3.8 and below, update to a version above 3.8 to resolve the issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2022-46676

Affected Products

Wyse Management Suite