CVE-2022-46754

HIGH

Wyse Management Suite <3.8 - Privilege Escalation

Title source: llm
STIX 2.1

Description

Wyse Management Suite 3.8 and below contain an improper access control vulnerability. A authenticated malicious admin user might access certain pro license features for which this admin is not authorized in order to configure user controlled external entities.

Scores

CVSS v3 8.7
EPSS 0.0029
EPSS Percentile 52.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-284
Status published
Products (1)
dell/wyse_management_suite < 3.8.0
Published Feb 11, 2023
Tracked Since Feb 18, 2026