PT-2025-13420 · Dell · Dell Unity

Published

2025-01-21

·

Updated

2025-07-08

·

CVE-2025-24383

CVSS v2.0

9.4

Critical

VectorAV:N/AC:L/Au:N/C:N/I:C/A:C
Name of the Vulnerable Software and Affected Versions Dell Unity versions 5.4 and prior
Description The issue is related to an Improper Neutralization of Special Elements used in an OS Command, also known as 'OS Command Injection'. This can be exploited by an unauthenticated attacker with remote access to delete arbitrary files, including critical system files as root. The vulnerability is considered critical.
Recommendations For Dell Unity versions 5.4 and prior, upgrade to version 5.5.0.0.5.259 at the earliest opportunity to resolve the issue. As a temporary workaround, consider restricting access to sensitive files and system resources to minimize the risk of exploitation.

Fix

LPE

OS Command Injection

Weakness Enumeration

Related Identifiers

BDU:2025-03555
CVE-2025-24383

Affected Products

Dell Unity