First published: Tue Dec 21 2021(Updated: )
Dell Wyse Management Suite version 3.3.1 and prior support insecure Transport Security Protocols TLS 1.0 and TLS 1.1 which are susceptible to Man-In-The-Middle attacks thereby compromising Confidentiality and Integrity of data.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dell Wyse Management Suite | <=3.3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-36337 is a vulnerability in Dell Wyse Management Suite versions 3.3.1 and prior that allows for insecure Transport Security Protocols TLS 1.0 and TLS 1.1, making it susceptible to Man-In-The-Middle attacks and compromising the Confidentiality and Integrity of data.
The severity of CVE-2021-36337 is high, with a CVSS score of 7.4.
CVE-2021-36337 affects Dell Wyse Management Suite versions 3.3.1 and prior by supporting insecure Transport Security Protocols TLS 1.0 and TLS 1.1, which can be exploited by Man-In-The-Middle attacks.
The impact of CVE-2021-36337 is the compromise of Confidentiality and Integrity of data due to the vulnerability in Dell Wyse Management Suite.
To fix CVE-2021-36337, it is recommended to update Dell Wyse Management Suite to a version that supports secure Transport Security Protocols such as TLS 1.2 or higher.