First published: Mon Jan 04 2021(Updated: )
Dell Wyse Management Suite versions prior to 3.1 contain an open redirect vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability to redirect application users to arbitrary web URLs by tricking the victim users to click on maliciously crafted links. The vulnerability could be used to conduct phishing attacks that cause users to unknowingly visit malicious sites.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dell Wyse Management Suite | <3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-29498 is an open redirect vulnerability in Dell Wyse Management Suite versions prior to 3.1.
CVE-2020-29498 allows remote unauthenticated attackers to redirect application users to arbitrary web URLs.
An attacker can exploit CVE-2020-29498 by tricking victim users into clicking on maliciously crafted links.
The severity of CVE-2020-29498 is medium with a CVSS score of 6.1.
To fix CVE-2020-29498, Dell Wyse Management Suite users should update to version 3.1 or higher.