ZeroHour

CVE-2026-81235

moderate

Missing Cryptographic Step in Dell Wyse Management Suite Prior to 2605.0.3.683

CVSS 3.1
8.0 high
EPSS
Published
()
Modified
AI analysis

Dell Wyse Management Suite (WMS) versions prior to 2605.0.3.683 contain a missing cryptographic step flaw (CWE-325), meaning a required cryptographic operation was omitted, weakening the protection of data handled by the suite. A remote attacker who already holds high-privileged (administrator-level) access to the WMS deployment could exploit this weakness to tamper with information, with CVSS 3.1 rating the worst-case impact as high for confidentiality, integrity, and availability across a changed scope. The attack requires high privileges and high complexity, so the practical risk is concentrated in environments where admin accounts or remote management access are already compromised or poorly controlled. Organizations running on-premises WMS releases older than 2605.0.3.683 are affected. There is no known public proof-of-concept, the issue is not on the CISA KEV catalog, and no exploitation in the wild has been reported.

What to do: Upgrade Dell Wyse Management Suite to version 2605.0.3.683 or later as soon as possible. Because exploitation requires high-privileged remote access, restrict WMS administrative interfaces to trusted networks/VPNs, enforce MFA on administrative accounts, and rotate privileged credentials. Audit WMS logs and managed-device configurations for any unexplained changes that could indicate information tampering.

Affected
Dell Wyse Management Suiteprior to 2605.0.3.683 (< 2605.0.3.683)
Estimated exposure
moderatelikely on the order of 1,000–10,000 WMS server deployments worldwide, each managing fleets of thin-client endpoints — Wyse Management Suite is per-organization management software with no published install counts; the estimate is inferred from Dell's substantial enterprise thin-client presence in healthcare, finance, and government, where each customer…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain a Missing Cryptographic Step vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Information tampering.

Weakness
CWE-325
Vector
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.