ID

VAR-202101-0521


CVE

CVE-2020-29498


TITLE

Dell Wyse Management Suite  Open redirect vulnerability

Trust: 0.8

sources: JVNDB: JVNDB-2020-015177

DESCRIPTION

Dell Wyse Management Suite versions prior to 3.1 contain an open redirect vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability to redirect application users to arbitrary web URLs by tricking the victim users to click on maliciously crafted links. The vulnerability could be used to conduct phishing attacks that cause users to unknowingly visit malicious sites. DELL Dell Wyse Management Suite is a scalable solution for managing and optimizing Wyse endpoints from Dell (DELL). The offering includes Wyse endpoint centralized management, asset tracking and automatic device discovery

Trust: 1.71

sources: NVD: CVE-2020-29498 // JVNDB: JVNDB-2020-015177 // VULHUB: VHN-376202

AFFECTED PRODUCTS

vendor:dellmodel:wyse management suitescope:ltversion:3.1

Trust: 1.0

vendor:デルmodel:dell wyse management suitescope:eqversion:3.1

Trust: 0.8

vendor:デルmodel:dell wyse management suitescope:eqversion: -

Trust: 0.8

sources: JVNDB: JVNDB-2020-015177 // NVD: CVE-2020-29498

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2020-29498
value: MEDIUM

Trust: 1.0

security_alert@emc.com: CVE-2020-29498
value: MEDIUM

Trust: 1.0

NVD: CVE-2020-29498
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-202101-031
value: MEDIUM

Trust: 0.6

VULHUB: VHN-376202
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2020-29498
severity: MEDIUM
baseScore: 5.8
vectorString: AV:N/AC:M/AU:N/C:P/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 4.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-376202
severity: MEDIUM
baseScore: 5.8
vectorString: AV:N/AC:M/AU:N/C:P/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 4.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

security_alert@emc.com: CVE-2020-29498
baseSeverity: MEDIUM
baseScore: 6.1
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: REQUIRED
scope: CHANGED
confidentialityImpact: LOW
integrityImpact: LOW
availabilityImpact: NONE
exploitabilityScore: 2.8
impactScore: 2.7
version: 3.0

Trust: 1.8

nvd@nist.gov: CVE-2020-29498
baseSeverity: MEDIUM
baseScore: 6.1
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: REQUIRED
scope: CHANGED
confidentialityImpact: LOW
integrityImpact: LOW
availabilityImpact: NONE
exploitabilityScore: 2.8
impactScore: 2.7
version: 3.1

Trust: 1.0

sources: VULHUB: VHN-376202 // JVNDB: JVNDB-2020-015177 // CNNVD: CNNVD-202101-031 // NVD: CVE-2020-29498 // NVD: CVE-2020-29498

PROBLEMTYPE DATA

problemtype:CWE-601

Trust: 1.1

problemtype:Open redirect (CWE-601) [NVD Evaluation ]

Trust: 0.8

sources: VULHUB: VHN-376202 // JVNDB: JVNDB-2020-015177 // NVD: CVE-2020-29498

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-202101-031

TYPE

input validation error

Trust: 0.6

sources: CNNVD: CNNVD-202101-031

PATCH

title:DSA-2020-282url:https://www.dell.com/support/kbdoc/ja-jp/000180983/dsa-2020-282

Trust: 0.8

title:Dell Wyse Management Suite Security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=138299

Trust: 0.6

sources: JVNDB: JVNDB-2020-015177 // CNNVD: CNNVD-202101-031

EXTERNAL IDS

db:NVDid:CVE-2020-29498

Trust: 2.5

db:JVNDBid:JVNDB-2020-015177

Trust: 0.8

db:CNNVDid:CNNVD-202101-031

Trust: 0.6

db:VULHUBid:VHN-376202

Trust: 0.1

sources: VULHUB: VHN-376202 // JVNDB: JVNDB-2020-015177 // CNNVD: CNNVD-202101-031 // NVD: CVE-2020-29498

REFERENCES

url:https://www.dell.com/support/kbdoc/en-us/000180983/dsa-2020-282

Trust: 1.7

url:https://nvd.nist.gov/vuln/detail/cve-2020-29498

Trust: 1.4

sources: VULHUB: VHN-376202 // JVNDB: JVNDB-2020-015177 // CNNVD: CNNVD-202101-031 // NVD: CVE-2020-29498

SOURCES

db:VULHUBid:VHN-376202
db:JVNDBid:JVNDB-2020-015177
db:CNNVDid:CNNVD-202101-031
db:NVDid:CVE-2020-29498

LAST UPDATE DATE

2024-11-23T22:11:09.290000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-376202date:2021-01-06T00:00:00
db:JVNDBid:JVNDB-2020-015177date:2021-09-14T03:15:00
db:CNNVDid:CNNVD-202101-031date:2021-01-12T00:00:00
db:NVDid:CVE-2020-29498date:2024-11-21T05:24:07.267

SOURCES RELEASE DATE

db:VULHUBid:VHN-376202date:2021-01-04T00:00:00
db:JVNDBid:JVNDB-2020-015177date:2021-09-14T00:00:00
db:CNNVDid:CNNVD-202101-031date:2021-01-04T00:00:00
db:NVDid:CVE-2020-29498date:2021-01-04T22:15:13.873