CVE-2021-36336: Critical severity Dell Wyse Management Suite vulnerability
Wyse Management Suite 3.3.1 and below versions contain a deserialization vulnerability that could allow an unauthenticated attacker to execute code on the affected system.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-36336?
CVE-2021-36336 is a deserialization vulnerability in Wyse Management Suite 3.3.1 and below versions that allows an unauthenticated attacker to execute code on the affected system.
How severe is CVE-2021-36336?
CVE-2021-36336 has a severity rating of 9.8, which is considered critical.
Which software versions are affected by CVE-2021-36336?
Wyse Management Suite versions up to and including 3.3.1 are affected by CVE-2021-36336.
How can an attacker exploit CVE-2021-36336?
An unauthenticated attacker can exploit CVE-2021-36336 by sending malicious data to the affected system, which triggers deserialization and allows execution of arbitrary code.
Is there a fix available for CVE-2021-36336?
Yes, Dell has provided a fix for CVE-2021-36336. It is recommended to update to a version of Wyse Management Suite that is not vulnerable.