CVE-2026-81235
moderateMissing Cryptographic Step in Dell Wyse Management Suite Prior to 2605.0.3.683
Dell Wyse Management Suite (WMS) versions prior to 2605.0.3.683 contain a missing cryptographic step flaw (CWE-325), meaning a required cryptographic operation was omitted, weakening the protection of data handled by the suite. A remote attacker who already holds high-privileged (administrator-level) access to the WMS deployment could exploit this weakness to tamper with information, with CVSS 3.1 rating the worst-case impact as high for confidentiality, integrity, and availability across a changed scope. The attack requires high privileges and high complexity, so the practical risk is concentrated in environments where admin accounts or remote management access are already compromised or poorly controlled. Organizations running on-premises WMS releases older than 2605.0.3.683 are affected. There is no known public proof-of-concept, the issue is not on the CISA KEV catalog, and no exploitation in the wild has been reported.
What to do: Upgrade Dell Wyse Management Suite to version 2605.0.3.683 or later as soon as possible. Because exploitation requires high-privileged remote access, restrict WMS administrative interfaces to trusted networks/VPNs, enforce MFA on administrative accounts, and rotate privileged credentials. Audit WMS logs and managed-device configurations for any unexplained changes that could indicate information tampering.
| Dell Wyse Management Suite | prior to 2605.0.3.683 (< 2605.0.3.683) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Dell Wyse Management Suite, versions prior to 2605.0.3.683, contain a Missing Cryptographic Step vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Information tampering.
- Weakness
- CWE-325
- Vector
- CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.