PT-2025-31809 · Dell · Dell Unity
Sina Kheirkhah
+1
·
Published
2025-08-04
·
Updated
2026-01-29
·
CVE-2025-36604
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Dell Unity versions prior to 5.5.1
Dell UnityVSA versions prior to 5.5.1
Description
Dell Unity and UnityVSA contain an Improper Neutralization of Special Elements used in an OS Command vulnerability, also known as OS Command Injection. An unauthenticated, remote attacker could potentially exploit this issue to execute arbitrary commands on the system. The vulnerability stems from improper handling of login redirect URIs, allowing an attacker to insert shell metacharacters into a command execution string during the redirect process. This could lead to unauthorized configuration changes, data access, or complete control over the appliance.
Recommendations
Upgrade to version 5.5.1 or later to address this vulnerability.
Exploit
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dell Unity