CVE-2025-27695
Description
Dell Wyse Management Suite, versions prior to WMS 5.1 contain an Authentication Bypass by Spoofing vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Information Disclosure.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A high-privileged remote attacker can bypass authentication via spoofing in Dell Wyse Management Suite before 5.1, leading to information disclosure.
Vulnerability
Dell Wyse Management Suite (WMS) versions prior to WMS 5.1 contain an Authentication Bypass by Spoofing vulnerability. The flaw resides in the proprietary code of the management suite and allows a high-privileged attacker with remote access to bypass authentication mechanisms by spoofing legitimate credentials or session identifiers. The affected versions include all builds of WMS before the 5.1 release [1].
Exploitation
To exploit this vulnerability, an attacker must have high privileges on the network (e.g., administrator or similarly elevated role) and remote access to the WMS instance. The attacker can spoof authentication tokens or impersonate a trusted entity to gain unauthorized entry. The exact sequence of steps is not detailed in the advisory, but the attack requires high privileges and does not require user interaction [1].
Impact
Successful exploitation leads to information disclosure. The attacker can access sensitive data managed by the WMS, such as device configurations, credentials, or other confidential information. The CVSS base score is not explicitly provided for this specific CVE in the reference, but the impact is rated as High by Dell [1].
Mitigation
Dell has addressed this vulnerability in WMS version 5.1. Users should upgrade to WMS 5.1 or later immediately. No workarounds are documented; upgrading is the only mitigation. The advisory does not list this CVE as part of the CISA Known Exploited Vulnerabilities catalog [1].
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: <5.1
- Range: N/A
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- www.dell.com/support/kbdoc/en-us/000296515/dsa-2025-135mitrevendor-advisory
News mentions
0No linked articles in our index yet.