PT-2025-44407 · Dell · Dell Unity

Published

2025-10-30

·

Updated

2025-11-07

·

CVE-2025-46423

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Dell Unity versions 5.5 and prior
Description Dell Unity versions 5.5 and earlier have an issue where special elements are not properly neutralized when used in operating system commands, potentially leading to OS Command Injection. An attacker with low privileges and local access could exploit this to execute arbitrary commands with root privileges.
Recommendations Update to a version of Dell Unity later than 5.5.

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2025-46423

Affected Products

Dell Unity