VYPR
Unrated severityNVD Advisory· Published Feb 10, 2023· Updated Mar 24, 2025

CVE-2022-46677

CVE-2022-46677

Description

Wyse Management Suite 3.8 and below contain an improper access control vulnerability with which an custom group admin can create a subgroup under a group for which the admin is not authorized.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

An authenticated malicious admin in Wyse Management Suite 3.8 and below can create a subgroup under a group they are not authorized to manage.

Vulnerability

Wyse Management Suite 3.8 and earlier contain an improper access control vulnerability [1]. A custom group admin with valid credentials can create a subgroup under a group for which they are not authorized to perform such actions [1]. The affected versions are 3.8 and below.

Exploitation

An attacker must be an authenticated admin user with group-level administrative privileges [1]. No additional network position or user interaction is required beyond the authenticated session [1]. The attacker can exploit this by navigating to the group management interface and creating a subgroup under a group outside their permitted scope [1].

Impact

Successful exploitation allows the attacker to create subgroups under unauthorized groups, leading to unauthorized access to group management functions [1]. This affects system integrity and availability without direct impact on confidentiality [1]. The CVSS v3.1 base score is 4.9 (Medium), with vector AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H, indicating a high availability impact [1].

Mitigation

Dell has released a security update; users should upgrade Wyse Management Suite to version 3.8.1 or later to address CVE-2022-46677 [1]. No workarounds are documented in the available references [1].

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.