CVE Vulnerabilities

CVE-2022-29090

Cleartext Storage of Sensitive Information in GUI

Published: Aug 10, 2022 | Modified: Nov 21, 2024
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Dell Wyse Management Suite 3.6.1 and below contains a Sensitive Data Exposure vulnerability. A low privileged malicious user could potentially exploit this vulnerability in order to obtain credentials. The attacker may be able to use the exposed credentials to access the target device and perform unauthorized actions.

Weakness

The product stores sensitive information in cleartext within the GUI.

Affected Software

Name Vendor Start Version End Version
Wyse_management_suite Dell * 3.8.0 (excluding)

References