CVE-2025-43940

7.8

Dell · Unity

Dell Unity systems contain an OS Command Injection vulnerability that allows local, low-privileged attackers to achieve command execution and escalate privileges.

Executive summary

Dell Unity storage systems are vulnerable to an OS Command Injection flaw that enables low-privileged local attackers to execute arbitrary commands and escalate their system privileges.

Vulnerability

The system fails to properly neutralize special elements used in OS commands, resulting in an OS Command Injection vulnerability. This flaw requires an attacker to have low-level local access to the device to trigger execution.

Business impact

The ability for a low-privileged user to execute arbitrary commands with elevated privileges poses a severe risk to data confidentiality, integrity, and availability. With a CVSS score of 7.8, this high-severity vulnerability could allow an attacker to compromise the entire storage array, leading to unauthorized data access or total system disruption.

Remediation

Immediate Action: Update all affected Dell Unity, UnityVSA, and Unity XT systems to version 5.5.2 or later as documented in the vendor security advisory DSA-2025-379.

Proactive Monitoring: Audit local system logs for unusual command execution patterns or unexpected administrative tasks initiated by non-administrative user accounts.

Compensating Controls: Restrict physical and logical access to the management console and command-line interface to trusted personnel only to mitigate the risk of local exploitation.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the potential for full system compromise via privilege escalation, administrators should prioritize the application of the vendor-supplied patch. Ensure that access control policies are strictly enforced to minimize the surface area available to potential local attackers until the update is deployed.

More Dell CVEs

Sources

Originally found and disclosed by Dell would like to thank zzcentury from Ubisectech Sirius Team for reporting this issue, per the CVE Program record.