CVE-2022-23158
01.04.2022, 20:15
Wyse Device Agent version 14.6.1.4 and below contain a sensitive data exposure vulnerability. A local authenticated user with standard privilege could potentially exploit this vulnerability and provide incorrect port information and get connected to valid WMS serverEnginsight
Vendor | Product | Version |
---|---|---|
dell | wyse_device_agent | 𝑥 ≤ 14.6.1.4 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-183 - Permissive List of Allowed InputsThe product implements a protection mechanism that relies on a list of inputs (or properties of inputs) that are explicitly allowed by policy because the inputs are assumed to be safe, but the list is too permissive - that is, it allows an input that is unsafe, leading to resultant weaknesses.
- CWE-200 - Exposure of Sensitive Information to an Unauthorized ActorThe product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.