CVE-2025-43942

7.8

Dell · Unity

Dell Unity storage systems contain an OS command injection vulnerability, allowing low-privileged local attackers to achieve command execution and privilege escalation.

Executive summary

A critical OS command injection vulnerability in Dell Unity storage systems allows local attackers with low privileges to execute arbitrary commands and escalate their access level.

Vulnerability

This is an OS command injection flaw (CWE-78) occurring when the system improperly neutralizes special elements in commands. The vulnerability requires the attacker to have local access and low-level privileges to successfully execute commands and escalate privileges.

Business impact

The ability to execute arbitrary OS commands and escalate privileges presents a significant risk to the confidentiality, integrity, and availability of stored data and management functions. With a CVSS score of 7.8, this high-severity flaw could allow an attacker to gain full control over the storage appliance, potentially leading to unauthorized data access or permanent system disruption.

Remediation

Immediate Action: Update all affected Dell Unity, UnityVSA, and Unity XT systems to version 5.5.2 or later as specified in the Dell security advisory DSA-2025-379.

Proactive Monitoring: Review system access logs for unauthorized attempts to execute administrative commands or unusual shell activity originating from low-privileged accounts.

Compensating Controls: Restrict local system access to authorized personnel only and ensure that administrative interfaces are isolated from untrusted network segments.

Exploitation status

Public Exploit Available: No — exploit_available (false).

Analyst recommendation

Given the potential for full system compromise via command injection, organizations should prioritize patching their Dell Unity infrastructure. Administrators must verify their current version against the 5.5.2 threshold and apply the vendor-supplied security updates as soon as operationally feasible to prevent unauthorized escalation.

More Dell CVEs

Sources

Originally found and disclosed by Dell would like to thank xiaohei from Ubisectech Sirius Team for reporting this issue, per the CVE Program record.