CVE-2022-29097
Description
Dell WMS 3.6.1 and below contains a Path Traversal vulnerability in Device API. A remote attacker could potentially exploit this vulnerability, to gain unauthorized read access to the files stored on the server filesystem, with the privileges of the running web application.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Dell Wyse Management Suite 3.6.1 and below contains a path traversal vulnerability in the Device API that allows an authenticated remote attacker to read arbitrary files on the server.
Vulnerability
A path traversal vulnerability exists in the Device API of Dell Wyse Management Suite (WMS) versions 3.6.1 and below. The flaw is present in proprietary code and allows an attacker to manipulate file paths via the API, leading to unauthorized file access on the server filesystem [1].
Exploitation
An attacker must be authenticated with high privileges (e.g., administrative access) and have network connectivity to the WMS server. By sending a specially crafted HTTP request to the vulnerable Device API endpoint with path traversal sequences (e.g., ../), the attacker can navigate outside the intended directory and read arbitrary files [1].
Impact
Successful exploitation grants the attacker read access to files stored on the server filesystem, with the privileges of the running web application. This results in a high confidentiality impact, potentially exposing sensitive configuration files, credentials, or other data. No integrity or availability impact is expected [1].
Mitigation
Dell has released a security update addressing this vulnerability as part of DSA-2022-143. Users should upgrade to the latest version of Wyse Management Suite as recommended in the advisory. No workarounds have been provided [1].
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: <=3.6.1
- Range: unspecified
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.