VYPR
Unrated severityNVD Advisory· Published Apr 2, 2025· Updated Apr 2, 2025

CVE-2025-27694

CVE-2025-27694

Description

Dell Wyse Management Suite, versions prior to WMS 5.1, contains an Insufficient Resource Pool vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Denial of service.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Dell Wyse Management Suite before WMS 5.1 has an insufficient resource pool vulnerability allowing unauthenticated remote attackers to cause a denial of service.

Vulnerability

CVE-2025-27694 is an insufficient resource pool vulnerability in Dell Wyse Management Suite (WMS) versions prior to 5.1 [1]. The vulnerability exists in proprietary code, where the resource pool management does not adequately limit concurrent connections or resource consumption, making the system susceptible to resource exhaustion.

Exploitation

An unauthenticated attacker with remote network access can exploit this vulnerability by sending a flood of requests or specially crafted data that exhausts the server's resource pool [1]. No authentication, user interaction, or special privileges are required, and the attack can be conducted over the network.

Impact

Successful exploitation leads to a denial of service (DoS) condition, where WMS becomes unresponsive or unable to process legitimate requests [1]. The CVSS v3.1 base score is 5.3 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L), indicating a low availability impact with no confidentiality or integrity loss.

Mitigation

The vulnerability is fixed in Dell Wyse Management Suite version 5.1, which was released on or before the advisory date of April 2, 2025 [1]. Users should update to WMS 5.1 or later. No workarounds are provided, and the advisory does not list this CVE in CISA's Known Exploited Vulnerabilities (KEV) catalog.

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.