CVE-2025-46422
7.8Dell · Unity
Dell Unity versions 5.5 and prior contain an OS command injection vulnerability that allows a local, low-privileged attacker to execute arbitrary commands with root privileges.
Executive summary
A critical OS command injection vulnerability in Dell Unity storage systems allows local authenticated attackers to achieve full root-level compromise.
Vulnerability
This vulnerability is an OS command injection flaw (CWE-78) occurring within the Dell Unity system. An attacker with low-level local access can inject special elements into system commands, resulting in execution at the root privilege level.
Business impact
The ability to execute arbitrary commands as root presents a significant threat to data confidentiality, integrity, and system availability. Given the CVSS score of 7.8, this vulnerability is classified as High severity because it allows a local attacker to bypass existing security boundaries and potentially gain full control over the storage appliance, leading to unauthorized data access or total system disruption.
Remediation
Immediate Action: Update all Dell Unity and Unity XT systems to version 5.5.2 or later as specified in Dell Security Advisory DSA-2025-379.
Proactive Monitoring: Audit local system access logs for unauthorized command execution or unusual privilege escalation attempts by service accounts.
Compensating Controls: Restrict physical and logical access to the management console to only highly trusted administrators to reduce the risk of local exploitation.
Exploitation status
Public Exploit Available: No
Analyst recommendation
This vulnerability represents a significant risk to the integrity of Dell Unity storage environments. Administrators must prioritize the application of the vendor-supplied security update to version 5.5.2 to eliminate the command injection vector. Failure to patch may allow an attacker with local access to assume complete control over the storage infrastructure.
More Dell CVEs
Sources
Originally found and disclosed by Dell would like to thank xiaohei from Ubisectech Sirius Team for reporting this issue, per the CVE Program record.