Show filters
5 Total Results
Displaying 1-5 of 5
Sort by:
Attacker Value
Unknown

CVE-2022-23158

Disclosure Date: February 17, 2022 (last updated February 23, 2025)
Wyse Device Agent version 14.6.1.4 and below contain a sensitive data exposure vulnerability. A local authenticated user with standard privilege could potentially exploit this vulnerability and provide incorrect port information and get connected to valid WMS server
Attacker Value
Unknown

CVE-2022-23156

Disclosure Date: February 17, 2022 (last updated February 23, 2025)
Wyse Device Agent version 14.6.1.4 and below contain an Improper Authentication vulnerability. A malicious user could potentially exploit this vulnerability by providing invalid input in order to obtain a connection to WMS server.
Attacker Value
Unknown

CVE-2022-23157

Disclosure Date: February 17, 2022 (last updated February 23, 2025)
Wyse Device Agent version 14.6.1.4 and below contain a sensitive data exposure vulnerability. A authenticated malicious user could potentially exploit this vulnerability in order to view sensitive information from the WMS Server.
Attacker Value
Unknown

CVE-2021-36341

Disclosure Date: December 06, 2021 (last updated February 23, 2025)
Dell Wyse Device Agent version 14.5.4.1 and below contain a sensitive data exposure vulnerability. A local authenticated user with low privileges could potentially exploit this vulnerability in order to access sensitive information.
Attacker Value
Unknown

DSA-2019-039: Dell Wyse Device Agent Buffer Overflow Vulnerability

Disclosure Date: March 07, 2019 (last updated November 27, 2024)
Dell WES Wyse Device Agent versions prior to 14.1.2.9 and Dell Wyse ThinLinux HAgent versions prior to 5.4.55 00.10 contain a buffer overflow vulnerability. An unauthenticated attacker may potentially exploit this vulnerability to execute arbitrary code on the system with privileges of the FTP client by sending specially crafted input data to the affected system. The FTP code that contained the vulnerability has been removed.
0