CVE-2025-43941

7.2

Dell · Unity

Dell Unity systems running versions 5.5 and prior are susceptible to OS Command Injection, allowing low-privileged attackers with local access to execute arbitrary commands with root privileges.

Executive summary

A critical OS Command Injection vulnerability in Dell Unity storage systems could allow a locally authenticated attacker to gain full root-level control over the appliance.

Vulnerability

The vulnerability is an Improper Neutralization of Special Elements used in an OS Command (CWE-78). It requires an attacker to possess low-level local privileges to trigger the injection, which then executes with root-level permissions.

Business impact

Successful exploitation of this flaw grants an attacker root-level access to the storage appliance, which could lead to full system compromise, data exfiltration, or total loss of storage availability. With a CVSS score of 7.2, this vulnerability represents a high risk to the confidentiality, integrity, and availability of sensitive infrastructure managed by the Dell Unity platform.

Remediation

Immediate Action: Update Dell Unity, UnityVSA, and Unity XT software to version 5.5.2 or later as specified in the vendor security advisory.

Proactive Monitoring: Audit system logs for unauthorized privilege escalation attempts or unusual command execution patterns originating from local user accounts.

Compensating Controls: Restrict physical and logical access to the management console to authorized personnel only, as the vulnerability requires a local authenticated session to exploit.

Exploitation status

Public Exploit Available: exploit_available (unknown)

Analyst recommendation

Given the potential for complete system compromise via root-level command execution, administrators should prioritize updating affected Dell Unity appliances to version 5.5.2. Ensure that access controls are strictly enforced to prevent unauthorized local access, which remains the primary vector for this vulnerability.

More Dell CVEs

Sources

Originally found and disclosed by Dell would like to thank xiaohei from Ubisectech Sirius Team for reporting this issue, per the CVE Program record.