First published: Wed Aug 10 2022(Updated: )
WMS 3.7 contains a Path Traversal Vulnerability in Device API. An attacker could potentially exploit this vulnerability, to gain unauthorized read access to the files stored on the server filesystem, with the privileges of the running web application.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dell Wyse Management Suite | <3.8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for the Path Traversal Vulnerability in Device API in WMS 3.7 is CVE-2022-34365.
The severity of CVE-2022-34365 is medium with a CVSS score of 6.5.
An attacker can potentially gain unauthorized read access to the files stored on the server filesystem by exploiting CVE-2022-34365.
Yes, Dell Wyse Management Suite versions up to and exclusive of 3.8.0 are affected by CVE-2022-34365.
You can find more information about CVE-2022-34365 in the Dell Wyse Management Suite Security Update for Multiple Vulnerabilities advisory at https://www.dell.com/support/kbdoc/en-us/000201383/dsa-2022-134-dell-wyse-management-suite-security-update-for-multiple-vulnerabilities.