CVE-2025-36578
Description
Dell Wyse Management Suite, versions prior to WMS 5.2, contain an Incorrect Authorization vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Dell Wyse Management Suite before 5.2 has an incorrect authorization vulnerability allowing low-privileged remote attackers to gain unauthorized access.
Vulnerability
Dell Wyse Management Suite (WMS) versions prior to 5.2 contain an Incorrect Authorization vulnerability [1]. This flaw exists in the proprietary code of WMS [1], allowing a low-privileged authenticated user to access resources or perform actions that should require higher privileges [1]. The vulnerability is present in all versions before WMS 5.2 [1].
Exploitation
An attacker with low privileges and remote access to the WMS instance can exploit this vulnerability [1]. The CVSS vector string (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N) indicates the attack complexity is low, and no user interaction is required [1]. The attacker must already have a low-privileged account on the WMS [1]. Specific exploitation steps are not detailed in the available references, but the nature of an incorrect authorization flaw typically involves sending crafted requests to endpoints that fail to properly verify the user's permission level.
Impact
Successful exploitation leads to unauthorized access, potentially resulting in high confidentiality and high integrity impact [1]. The attacker could read sensitive information (e.g., configuration data, other users' data) and modify data they should not have write access to [1]. Availability is not affected [1]. Given that Dell rated the overall impact as 'High', this vulnerability could enable an attacker to compromise critical WMS functions [1].
Mitigation
Dell has fixed this vulnerability in Wyse Management Suite version 5.2 [1]. All users running WMS prior to 5.2 should upgrade to version 5.2 or later as soon as possible [1]. No workarounds have been published. According to the advisory, this CVE is not listed on CISA's Known Exploited Vulnerabilities (KEV) catalog as of the publication date.
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: <5.2
- Range: N/A
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- www.dell.com/support/kbdoc/en-us/000325679/dsa-2025-226mitrevendor-advisory
News mentions
0No linked articles in our index yet.