Dell Wyse Management Suite: Attackers can bypass security mechanisms
Dell's developers have closed several vulnerabilities in the client management software WMS.
(Image: Artur Szczybylo/Shutterstock.com)
Admins who manage clients in companies with Dell Wyse Management Suite (WMS) should update the software promptly. Otherwise, attackers can exploit five vulnerabilities and delete files, among other things.
Security update available
According to a warning message, DoS attacks (CVE-2024-49595"high") are conceivable, and attackers can also bypass unspecified security mechanisms (CVE-2024-49597"high"). In both cases, remote attacks are possible, but attackers already require high user rights.
Videos by heise
So far, there are no indications of attacks by the computer manufacturer. The developers claim to have solved the security problems in Dell WMS 4.4.1. All previous versions are vulnerable.
(des)