Dell Unity OS Command Injection Vulnerability Allowing Privilege Escalation

Vulnerability

A command injection vulnerability has been identified in Dell Unity versions through 5.5. Low privileged attackers with local access can exploit this issue to execute arbitrary commands with root privileges. The vulnerability affects systems without a valid license installation.

Impact

Exploitation of this vulnerability allows for arbitrary command execution with root privileges, potentially leading to unauthorized access or modification of system resources.

Remediation

Users can upgrade to Dell Unity version 5.5.2 or later. Instructions for downloading the update are available on the Dell Unity All-Flash Family Drivers page.

Added: Oct 30, 2025, 2:19 PM
Updated: Oct 30, 2025, 3:06 PM

Vulnerability Rating

Custom Algorithm
spread
4.5
impact
7.5
exploitability
3.5
remediation
7.7
relevance
0.9
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.