PT-2025-39410 · Dell · Cloud Disaster Recovery

Published

2025-09-25

·

Updated

2025-09-25

·

CVE-2025-43943

CVSS v3.1

6.7

Medium

VectorAV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Dell Cloud Disaster Recovery versions prior to 19.20
Description Dell Cloud Disaster Recovery contains an Improper Neutralization of Special Elements used in an OS Command, also known as OS Command Injection. A high privileged attacker with local access could potentially exploit this to execute arbitrary commands with root privileges.
Recommendations Update Dell Cloud Disaster Recovery to version 19.20 or later.

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-43943

Affected Products

Cloud Disaster Recovery