6.7
/ 10
MEDIUM
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Description
Dell Cloud Disaster Recovery, version(s) prior to 19.20, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability to execute arbitrary commands with root privileges.
Basic Information
ID
CVE-2025-43943
Source
dell
Published
Sep 25, 2025 at 15:22
Affected Product
Vendor
Dell
Product
Cloud Disaster Recovery
Version
N/A
Affected Versions
Dell Cloud Disaster Recovery N/A