CVE-2022-29097
Last modified
CVE-2022-29097 is a medium-severity vulnerability rated 4.9/10 on the CVSS scale. Dell WMS 3.6.1 and below contains a Path Traversal vulnerability in Device API. A remote attacker could potentially exploit this vulnerability, to gain unauthorized read access to the files stored on the server filesystem, with the privileges of the running web application.. EPSS estimates a 1.21% chance of exploitation in the next 30 days.
Description
Dell WMS 3.6.1 and below contains a Path Traversal vulnerability in Device API. A remote attacker could potentially exploit this vulnerability, to gain unauthorized read access to the files stored on the server filesystem, with the privileges of the running web application.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Dell | Wyse Management Suite | <= 3.6.1 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-29097?
How severe is CVE-2022-29097?
How do I fix CVE-2022-29097?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-29091Dell Unity, Dell UnityVSA, and Dell UnityXT versions prior t…6.1
- CVE-2022-29092Dell SupportAssist Client Consumer versions (3.11.0 and vers…7.8
- CVE-2022-29093Dell SupportAssist Client Consumer versions (3.10.4 and vers…7.1
- CVE-2022-29094Dell SupportAssist Client Consumer versions (3.10.4 and vers…7.1
- CVE-2022-29095Dell SupportAssist Client Consumer versions (3.10.4 and prio…9.6
- CVE-2022-29096Dell Wyse Management Suite 3.6.1 and below contains a Reflec…5.4
- CVE-2022-29098Dell PowerScale OneFS versions 8.2.0.x through 9.3.0.x, cont…7.5
- CVE-2022-29099Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2022-29100Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2022-29101Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2022-29102Windows Failover Cluster Information Disclosure Vulnerabilit…5.5
- CVE-2022-29103Windows Remote Access Connection Manager Elevation of Privil…7.8
Are you affected by CVE-2022-29097?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
