VYPR
Unrated severityNVD Advisory· Published Aug 10, 2022· Updated Sep 17, 2024

CVE-2022-33928

CVE-2022-33928

Description

Dell Wyse Management Suite 3.6.1 and below contains an Plain-text Password Storage Vulnerability in UI. An attacker with low privileges could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials to access the vulnerable application with privileges of the compromised account.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Dell Wyse Management Suite 3.6.1 and below stores passwords in plain text in the UI, allowing low-privilege attackers to obtain user credentials.

Vulnerability

Dell Wyse Management Suite versions 3.6.1 and earlier contain a plain-text password storage vulnerability in the user interface [1]. The application stores certain user credentials in an unencrypted plain-text format within the UI layer, making them accessible to anyone with low-level access to the management interface [1]. This affects all versions up to and including 3.6.1.

Exploitation

An attacker with low privileges on the Wyse Management Suite can access the UI component where credentials are stored in plain text [1]. The attacker does not require any special authentication beyond their existing low-privileged session. By navigating to the relevant UI elements, the attacker can read the exposed credentials directly [1]. No user interaction or complex preparatory steps are necessary for this exploitation.

Impact

Successful exploitation leads to the disclosure of certain user credentials, including those of other users with potentially higher privileges [1]. The attacker can then use the compromised credentials to log in to the vulnerable application and gain the privileges of the compromised account [1]. This could allow the attacker to perform actions or access data that would otherwise be restricted.

Mitigation

Dell released a security update for Wyse Management Suite to address this vulnerability. According to the advisory, the fix is included in version 3.7 or later [1]. Users should upgrade to version 3.7 or the latest available version as soon as possible. No workarounds are mentioned in the available references. This CVE is not listed on the CISA Known Exploited Vulnerabilities (KEV) catalog as of the publication date.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.