CVE-2022-29097: Path Traversal
Dell WMS 3.6.1 and below contains a Path Traversal vulnerability in Device API. A remote attacker could potentially exploit this vulnerability, to gain unauthorized read access to the files stored on the server filesystem, with the privileges of the running web application.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this Dell WMS vulnerability?
The vulnerability ID for this Dell WMS vulnerability is CVE-2022-29097.
What is the severity of CVE-2022-29097?
The severity of CVE-2022-29097 is medium (4.9).
How does the Path Traversal vulnerability in Dell WMS work?
The Path Traversal vulnerability in Dell WMS allows a remote attacker to gain unauthorized read access to the files stored on the server filesystem, with the privileges of the running web application.
Which version of Dell Wyse Management Suite is affected by this vulnerability?
This vulnerability affects Dell Wyse Management Suite version 3.6.1 and below.
Is there a security update available for Dell WMS to fix this vulnerability?
Yes, Dell has released a security update to address this vulnerability. Please refer to the official Dell support website for more information.