CVE-2025-43940
7.8Dell · Unity
Dell Unity systems contain an OS Command Injection vulnerability that allows local, low-privileged attackers to achieve command execution and escalate privileges.
Executive summary
Dell Unity storage systems are vulnerable to an OS Command Injection flaw that enables low-privileged local attackers to execute arbitrary commands and escalate their system privileges.
Vulnerability
The system fails to properly neutralize special elements used in OS commands, resulting in an OS Command Injection vulnerability. This flaw requires an attacker to have low-level local access to the device to trigger execution.
Business impact
The ability for a low-privileged user to execute arbitrary commands with elevated privileges poses a severe risk to data confidentiality, integrity, and availability. With a CVSS score of 7.8, this high-severity vulnerability could allow an attacker to compromise the entire storage array, leading to unauthorized data access or total system disruption.
Remediation
Immediate Action: Update all affected Dell Unity, UnityVSA, and Unity XT systems to version 5.5.2 or later as documented in the vendor security advisory DSA-2025-379.
Proactive Monitoring: Audit local system logs for unusual command execution patterns or unexpected administrative tasks initiated by non-administrative user accounts.
Compensating Controls: Restrict physical and logical access to the management console and command-line interface to trusted personnel only to mitigate the risk of local exploitation.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the potential for full system compromise via privilege escalation, administrators should prioritize the application of the vendor-supplied patch. Ensure that access control policies are strictly enforced to minimize the surface area available to potential local attackers until the update is deployed.
More Dell CVEs
Sources
Originally found and disclosed by Dell would like to thank zzcentury from Ubisectech Sirius Team for reporting this issue, per the CVE Program record.