CVE-2021-36337: Weak Encryption
Dell Wyse Management Suite version 3.3.1 and prior support insecure Transport Security Protocols TLS 1.0 and TLS 1.1 which are susceptible to Man-In-The-Middle attacks thereby compromising Confidentiality and Integrity of data.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-36337?
CVE-2021-36337 is a vulnerability in Dell Wyse Management Suite versions 3.3.1 and prior that allows for insecure Transport Security Protocols TLS 1.0 and TLS 1.1, making it susceptible to Man-In-The-Middle attacks and compromising the Confidentiality and Integrity of data.
What is the severity of CVE-2021-36337?
The severity of CVE-2021-36337 is high, with a CVSS score of 7.4.
How does CVE-2021-36337 affect Dell Wyse Management Suite?
CVE-2021-36337 affects Dell Wyse Management Suite versions 3.3.1 and prior by supporting insecure Transport Security Protocols TLS 1.0 and TLS 1.1, which can be exploited by Man-In-The-Middle attacks.
What is the impact of CVE-2021-36337?
The impact of CVE-2021-36337 is the compromise of Confidentiality and Integrity of data due to the vulnerability in Dell Wyse Management Suite.
How can I fix CVE-2021-36337?
To fix CVE-2021-36337, it is recommended to update Dell Wyse Management Suite to a version that supports secure Transport Security Protocols such as TLS 1.2 or higher.