CVE-2021-21587
Description
Dell Wyse Management Suite versions 3.2 and earlier contain a full path disclosure vulnerability. A local unauthenticated attacker could exploit this vulnerability in order to obtain the path of files and folders.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Dell Wyse Management Suite versions 3.2 and earlier expose internal file and folder paths to a local unauthenticated attacker, aiding further reconnaissance.
Vulnerability
Dell Wyse Management Suite versions 3.2 and earlier contain a full path disclosure vulnerability [1]. A local unauthenticated attacker can exploit this issue to obtain the path of files and folders on the system [1]. The vulnerability affects all versions up to and including 3.2 [1].
Exploitation
The attacker needs local access to the system running Wyse Management Suite [1]. No authentication is required [1]. The attacker can leverage the vulnerability to discover internal file paths, which may be used to plan further attacks [1].
Impact
Successful exploitation results in the disclosure of file and folder paths [1]. This is a low-severity information leak (CVSS 5.3) with no direct impact on integrity or availability [1]. However, the leaked paths can assist in targeted attacks, such as path traversal or file reads [1].
Mitigation
Dell has released an update to address this vulnerability; customers should upgrade to Wyse Management Suite version 3.3 or later [1]. If an immediate update is not possible, Dell recommends following general security best practices for local access controls [1].
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: <=3.2
- Range: unspecified
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- www.dell.com/support/kbdoc/000189363mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.