Dell Unity OS Command Injection Vulnerability Allowing Privilege Escalation

Vulnerability

A command injection vulnerability has been identified in Dell Unity versions through 5.4. This vulnerability allows a low-privileged attacker with local access to execute arbitrary operating system commands with root privileges, potentially leading to a complete compromise of the system. The issue arises from improper handling of special elements in command execution.

Impact

Exploitation of this vulnerability could result in unauthorized command execution with elevated privileges, allowing an attacker to gain root access and potentially take over the system.

Remediation

Users are advised to upgrade to Dell Unity version 5.5.0.0.5.259 or later. Instructions for downloading the update are available on the Dell Support website.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
4.5
impact
7.5
exploitability
3.5
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.