VYPR
Unrated severityNVD Advisory· Published Aug 10, 2022· Updated Sep 16, 2024

CVE-2022-33930

CVE-2022-33930

Description

Dell Wyse Management Suite 3.6.1 and below contains Information Disclosure in Devices error pages. An attacker could potentially exploit this vulnerability, leading to the disclosure of certain sensitive information. The attacker may be able to use the exposed information to access and further vulnerability research.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Dell Wyse Management Suite 3.6.1 and below discloses sensitive information in error pages, aiding further attacks.

Vulnerability

Dell Wyse Management Suite versions 3.6.1 and below contain an information disclosure vulnerability in the Devices error pages. The error pages may inadvertently expose sensitive information to an attacker without proper authentication.

Exploitation

An attacker with network access to the Wyse Management Suite can trigger error pages by sending crafted requests. No special privileges are required, as the error pages are accessible without authentication. By analyzing the error page content, the attacker can extract sensitive data.

Impact

Successful exploitation results in the disclosure of sensitive information, which could include configuration details, internal paths, or user data. This information can be leveraged for further attacks, such as privilege escalation or additional vulnerability research.

Mitigation

Dell has released a security advisory (DSA-2022-134) addressing multiple vulnerabilities, including CVE-2022-33930. Users should upgrade to Wyse Management Suite version 3.7 or later, which contains the fix. No workarounds are documented; upgrading is the recommended mitigation [1].

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.