First published: Wed Aug 10 2022(Updated: )
Dell Wyse Management Suite 3.6.1 and below contains a Session Fixation vulnerability. A unauthenticated attacker could exploit this by taking advantage of a user with multiple active sessions in order to hijack a user's session.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dell Wyse Management Suite | <3.8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-33927.
The severity of CVE-2022-33927 is medium (CVSS score of 6.5).
The affected software is Dell Wyse Management Suite versions 3.6.1 and below.
An unauthenticated attacker can exploit CVE-2022-33927 by taking advantage of a user with multiple active sessions to hijack a user's session.
To fix CVE-2022-33927, it is recommended to update Dell Wyse Management Suite to version 3.8.0 or above.