To fix security flaws, Wyse Management Suite must be updated to version 5.5 or higher.
Russian Positive Technologies helped Dell improve the security of its thin client management solution. Company expert Alexander Zhurnakov identified a chain of vulnerabilities in the Wyse Management Suite software complex, designed for centralized device management. Successful exploitation of these vulnerabilities could lead to disruption of operational processes, data theft, and advancement within the company's infrastructure.
A security update released by Dell addresses vulnerabilities PT-2026-21793 and PT-2026-21794, which were assigned high severity levels on the CVSS 3.1 scale. The first vulnerability allowed an ordinary user to escalate privileges to administrator, and the second allowed uploading a malicious file and executing arbitrary code. Alexander Zhurnakov noted:
Vulnerabilities related to business logic flaws are often found in software complexes with broad functionality, such as Wyse Management Suite. It is almost impossible to fully maintain the security of such an extensive codebase without specialized solutions. To reduce risks, access to such software products from an external network should be restricted.
