PT-2023-23816 · Dell · Wyse Management Suite
Published
2023-07-20
·
Updated
2023-07-26
·
CVE-2023-32482
CVSS v3.1
4.9
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Wyse Management Suite versions prior to 4.0
Description
The issue is related to improper authorization, allowing an authenticated malicious user with privileged access to push policies to unauthorized tenant groups.
Recommendations
For Wyse Management Suite versions prior to 4.0, update to version 4.0 or later to resolve the issue. As a temporary workaround, consider restricting access to policy management features to minimize the risk of unauthorized policy pushes.
Fix
Incorrect Authorization
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Wyse Management Suite