Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability to delete arbitrary files. This vulnerability is considered critical as it can be leveraged to delete critical system files as root. Dell recommends customers to upgrade at the earliest opportunity.
                
            References
                    Configurations
                    History
                    08 Jul 2025, 16:33
| Type | Values Removed | Values Added | 
|---|---|---|
| Summary | 
 | |
| References | () https://www.dell.com/support/kbdoc/en-us/000300090/dsa-2025-116-security-update-for-dell-unity-dell-unityvsa-and-dell-unity-xt-security-update-for-multiple-vulnerabilities - Vendor Advisory | |
| CPE | cpe:2.3:a:dell:unity_operating_environment:*:*:*:*:*:*:*:* | |
| First Time | Dell Dell unity Operating Environment | 
28 Mar 2025, 03:15
| Type | Values Removed | Values Added | 
|---|---|---|
| CVSS | v2 : v3 : | v2 : unknown v3 : 9.1 | 
| Summary | (en) Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability to delete arbitrary files. This vulnerability is considered critical as it can be leveraged to delete critical system files as root. Dell recommends customers to upgrade at the earliest opportunity. | 
28 Mar 2025, 02:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2025-03-28 02:15
Updated : 2025-07-08 16:33
NVD link : CVE-2025-24383
Mitre link : CVE-2025-24383
CVE.ORG link : CVE-2025-24383
JSON object : View
Products Affected
                dell
- unity_operating_environment
CWE
                
                    
                        
                        CWE-78
                        
            Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
