Dell Unity OS Command Injection Vulnerability Allowing Arbitrary File Deletion

Vulnerability

A critical OS command injection vulnerability has been identified in Dell Unity versions through 5.4. This vulnerability allows an unauthenticated attacker with remote access to delete arbitrary files, including critical system files, with root privileges. Exploitation of this vulnerability could lead to severe system disruption or compromise.

Impact

Successful exploitation allows for arbitrary file deletion as root, potentially leading to system instability or compromise.

Remediation

Dell recommends upgrading to version 5.5.0.0.5.259 or later. Instructions for downloading the update are available on the Dell Unity All-Flash Family Drivers page.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
4.5
impact
2.5
exploitability
7.0
remediation
7.7
relevance
0.0
threat
0.1
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.