VYPR
Unrated severityNVD Advisory· Published Jun 10, 2025· Updated Jun 10, 2025

CVE-2025-36574

CVE-2025-36574

Description

Dell Wyse Management Suite, versions prior to WMS 5.2, contain an Absolute Path Traversal vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure and Unauthorized access.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

An unauthenticated remote attacker can exploit absolute path traversal in Dell Wyse Management Suite (<5.2) to read arbitrary files and gain unauthorized access.

Vulnerability

Dell Wyse Management Suite (WMS) versions prior to 5.2 contain an Absolute Path Traversal vulnerability in proprietary code. An unauthenticated attacker with remote access can send specially crafted requests to cause the server to read files outside the intended directory, leading to information disclosure and unauthorized access. The vulnerability is assigned CVSSv3.1 score 8.2 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N) [1].

Exploitation

No authentication or user interaction is required. The attacker only needs network access to the WMS management console or API endpoints. By manipulating input parameters (such as file paths or file names) in HTTP requests, the attacker can traverse directories and access arbitrary files on the server filesystem. The attack complexity is low, and no special privileges are needed [1].

Impact

Successful exploitation allows an unauthenticated attacker to read sensitive files (confidential configuration, credentials, or other data) from the server, resulting in high confidentiality impact. The low integrity impact indicates that the attacker may also be able to write or modify limited data, contributing to unauthorized access beyond mere passive reconnaissance [1].

Mitigation

The vulnerability is fixed in Dell Wyse Management Suite version 5.2. Dell strongly recommends upgrading to WMS 5.2 or later to remediate the issue. No workarounds or mitigations for earlier versions have been released. The advisory DSA-2025-226 provides full details [1].

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.