CVE-2025-46423

7.8

Dell · Unity

Dell Unity versions 5.5 and prior are vulnerable to OS command injection, allowing low-privileged local attackers to execute arbitrary commands with root privileges.

Executive summary

A high-severity OS command injection vulnerability in Dell Unity storage systems allows local authenticated attackers to achieve root-level code execution.

Vulnerability

The software contains an improper neutralization of special elements used in an OS command (CWE-78), which can be triggered by a low-privileged user with local access to the system to execute commands as root.

Business impact

Successful exploitation of this vulnerability grants an attacker full control over the affected storage appliance, leading to total compromise of data confidentiality, integrity, and availability. Given the high CVSS score of 7.8, this flaw represents a significant risk to the storage infrastructure, potentially enabling an attacker to pivot within the network or permanently disrupt business-critical data services.

Remediation

Immediate Action: Update Dell Unity, Dell UnityVSA, and Dell Unity XT systems to version 5.5.2 or later as specified in Dell Security Advisory DSA-2025-379.

Proactive Monitoring: Review system access logs for unusual command execution patterns or unauthorized attempts to escalate privileges by existing local accounts.

Compensating Controls: Restrict local shell access to the Unity appliance exclusively to authorized administrative personnel to minimize the exposure to low-privileged actors.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Security teams must prioritize patching Dell Unity systems to version 5.5.2 to eliminate the risk of root-level command injection. Given the potential for full system takeover, administrators should verify that only trusted personnel maintain local access to these appliances until the update is successfully applied.

More Dell CVEs

Sources

Originally found and disclosed by Dell would like to thank xiaohei from Ubisectech Sirius Team for reporting this issue, per the CVE Program record.