First published: Thu Nov 18 2021(Updated: )
Wyse Management Suite 3.3.1 and below versions contain a deserialization vulnerability that could allow an unauthenticated attacker to execute code on the affected system.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dell Wyse Management Suite | <=3.3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-36336 is a deserialization vulnerability in Wyse Management Suite 3.3.1 and below versions that allows an unauthenticated attacker to execute code on the affected system.
CVE-2021-36336 has a severity rating of 9.8, which is considered critical.
Wyse Management Suite versions up to and including 3.3.1 are affected by CVE-2021-36336.
An unauthenticated attacker can exploit CVE-2021-36336 by sending malicious data to the affected system, which triggers deserialization and allows execution of arbitrary code.
Yes, Dell has provided a fix for CVE-2021-36336. It is recommended to update to a version of Wyse Management Suite that is not vulnerable.