VYPR
Unrated severityNVD Advisory· Published Jun 24, 2022· Updated Sep 16, 2024

CVE-2022-29097

CVE-2022-29097

Description

Dell WMS 3.6.1 and below contains a Path Traversal vulnerability in Device API. A remote attacker could potentially exploit this vulnerability, to gain unauthorized read access to the files stored on the server filesystem, with the privileges of the running web application.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Dell Wyse Management Suite 3.6.1 and below contains a path traversal vulnerability in the Device API that allows an authenticated remote attacker to read arbitrary files on the server.

Vulnerability

A path traversal vulnerability exists in the Device API of Dell Wyse Management Suite (WMS) versions 3.6.1 and below. The flaw is present in proprietary code and allows an attacker to manipulate file paths via the API, leading to unauthorized file access on the server filesystem [1].

Exploitation

An attacker must be authenticated with high privileges (e.g., administrative access) and have network connectivity to the WMS server. By sending a specially crafted HTTP request to the vulnerable Device API endpoint with path traversal sequences (e.g., ../), the attacker can navigate outside the intended directory and read arbitrary files [1].

Impact

Successful exploitation grants the attacker read access to files stored on the server filesystem, with the privileges of the running web application. This results in a high confidentiality impact, potentially exposing sensitive configuration files, credentials, or other data. No integrity or availability impact is expected [1].

Mitigation

Dell has released a security update addressing this vulnerability as part of DSA-2022-143. Users should upgrade to the latest version of Wyse Management Suite as recommended in the advisory. No workarounds have been provided [1].

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.