CVE-2021-21586
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 8.1epss 4.0%
exploitation probability
4.0%top 10% of all CVEs
observed exploitation
nono source reports it
In short
Wyse Management Suite allows authenticated users to read any file on the system by bypassing file access restrictions. An attacker with login credentials could view sensitive information like passwords or configuration files.
Technical detail
Absolute path traversal vulnerability in Wyse Management Suite ≤3.2 enables authenticated attackers to read arbitrary files via improper path validation. Attack vector requires valid credentials; impact includes unauthorized information disclosure of system files.
Summary generated and translated by AI from the official description.
Wyse Management Suite versions 3.2 and earlier contain an absolute path traversal vulnerability. A remote authenticated malicious user could exploit this vulnerability in order to read arbitrary files on the system.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
Dell · Wyse Management Suite