Dell Unity OS Command Injection Vulnerability Allowing Arbitrary Command Execution

Vulnerability

A command injection vulnerability has been identified in Dell Unity versions through 5.4. This vulnerability allows an unauthenticated attacker with remote access to execute arbitrary commands on the system with root privileges. The issue arises from improper handling of special elements in operating system commands, which could be exploited to gain unauthorized access or control over the system.

Impact

Exploitation of this vulnerability could lead to unauthorized execution of commands with root privileges, allowing for complete control over the affected system.

Remediation

Users are advised to upgrade to version 5.5.0.0.5.259 or later. Instructions for downloading the update are available on the Dell Unity All-Flash Family Drivers page.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
4.5
impact
10.0
exploitability
7.0
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.