7.2
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Description
Dell Unity, version(s) 5.5 and Prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability to execute arbitrary command with root privileges. This vulnerability only affects systems without a valid license install.
Basic Information
ID
CVE-2025-43941
Source
dell
Published
Oct 30, 2025 at 13:57
Modified
Oct 30, 2025 at 14:29
Affected Product
Vendor
Dell
Product
Unity
Version
N/A
Affected Versions
Dell Unity N/A