CVE-2025-43941
7.2Dell · Unity
Dell Unity systems running versions 5.5 and prior are susceptible to OS Command Injection, allowing low-privileged attackers with local access to execute arbitrary commands with root privileges.
Executive summary
A critical OS Command Injection vulnerability in Dell Unity storage systems could allow a locally authenticated attacker to gain full root-level control over the appliance.
Vulnerability
The vulnerability is an Improper Neutralization of Special Elements used in an OS Command (CWE-78). It requires an attacker to possess low-level local privileges to trigger the injection, which then executes with root-level permissions.
Business impact
Successful exploitation of this flaw grants an attacker root-level access to the storage appliance, which could lead to full system compromise, data exfiltration, or total loss of storage availability. With a CVSS score of 7.2, this vulnerability represents a high risk to the confidentiality, integrity, and availability of sensitive infrastructure managed by the Dell Unity platform.
Remediation
Immediate Action: Update Dell Unity, UnityVSA, and Unity XT software to version 5.5.2 or later as specified in the vendor security advisory.
Proactive Monitoring: Audit system logs for unauthorized privilege escalation attempts or unusual command execution patterns originating from local user accounts.
Compensating Controls: Restrict physical and logical access to the management console to authorized personnel only, as the vulnerability requires a local authenticated session to exploit.
Exploitation status
Public Exploit Available: exploit_available (unknown)
Analyst recommendation
Given the potential for complete system compromise via root-level command execution, administrators should prioritize updating affected Dell Unity appliances to version 5.5.2. Ensure that access controls are strictly enforced to prevent unauthorized local access, which remains the primary vector for this vulnerability.
More Dell CVEs
Sources
Originally found and disclosed by Dell would like to thank xiaohei from Ubisectech Sirius Team for reporting this issue, per the CVE Program record.