cbcvebase.

Dell Unity Operating Environment vulnerabilities

53 known vulnerabilities affecting dell/unity_operating_environment.

Total CVEs
53
CISA KEV
0
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL5HIGH36MEDIUM12

Vulnerabilities

Page 1 of 3
CVE-2025-36604P1CRITICALCVSS 9.8ExploitedPoCfixed in 5.5.1.02025-08-04
CVE-2025-36604 [CRITICAL] CWE-78 CVE-2025-36604: Dell Unity, version(s) 5.5 and prior, contain(s) an Improper Neutralization of Special Elements used Dell Unity, version(s) 5.5 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to arbitrary command execution.
nvd
CVE-2025-22398P2CRITICALCVSS 9.8fixed in 5.5.0.0.5.2592025-03-28
CVE-2025-22398 [CRITICAL] CWE-78 CVE-2025-22398: Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to arbitrary command execution as root. Exploitation may lead to a system take over by an a
nvd
CVE-2024-49601P2CRITICALCVSS 9.8fixed in 5.5.0.0.5.2592025-03-28
CVE-2024-49601 [CRITICAL] CWE-78 CVE-2024-49601: Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Command execution.
nvd
CVE-2025-24383P2CRITICALCVSS 9.1fixed in 5.5.0.0.5.2592025-03-28
CVE-2025-24383 [CRITICAL] CWE-78 CVE-2025-24383: Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability to delete arbitrary files. This vulnerability is considered critical as it can be leveraged to delet
nvd
CVE-2022-29084P2CRITICALCVSS 9.8fixed in 5.2.0.0.5.1732022-06-02
CVE-2022-29084 [CRITICAL] CWE-307 CVE-2022-29084: Dell Unity, Dell UnityVSA, and Dell Unity XT versions before 5.2.0.0.5.173 do not restrict excessive Dell Unity, Dell UnityVSA, and Dell Unity XT versions before 5.2.0.0.5.173 do not restrict excessive authentication attempts in Unisphere GUI. A remote unauthenticated attacker may potentially exploit this vulnerability to brute-force passwords and gain access to the system as the victim. Account takeover is possible if weak passwords are used by
nvd
CVE-2025-46423P3HIGHCVSS 7.8fixed in 5.5.2.02025-10-30
CVE-2025-46423 [HIGH] CWE-78 CVE-2025-46423: Dell Unity, version(s) 5.5 and prior, contain(s) an Improper Neutralization of Special Elements used Dell Unity, version(s) 5.5 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability to execute arbitrary commands with root privileges.
nvd
CVE-2025-46422P3HIGHCVSS 7.8fixed in 5.5.2.02025-10-30
CVE-2025-46422 [HIGH] CWE-78 CVE-2025-46422: Dell Unity, version(s) 5.5 and prior, contain(s) an Improper Neutralization of Special Elements used Dell Unity, version(s) 5.5 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability to execute arbitrary commands with root privileges.
nvd
CVE-2025-24382P3HIGHCVSS 7.3fixed in 5.5.0.0.5.2592025-03-28
CVE-2025-24382 [HIGH] CWE-78 CVE-2025-24382: Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Command execution.
nvd
CVE-2025-43941P3HIGHCVSS 7.8fixed in 5.5.2.02025-10-30
CVE-2025-43941 [HIGH] CWE-78 CVE-2025-43941: Dell Unity, version(s) 5.5 and Prior, contain(s) an Improper Neutralization of Special Elements used Dell Unity, version(s) 5.5 and Prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability to execute arbitrary command with root privileges. This vulnerability only affects systems without a valid
nvd
CVE-2026-22277P3HIGHCVSS 7.8fixed in 5.5.3.02026-01-30
CVE-2026-22277 [HIGH] CWE-78 CVE-2026-22277: Dell UnityVSA, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements u Dell UnityVSA, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary command execution with root privileges.
nvd
CVE-2026-21418P3HIGHCVSS 7.8fixed in 5.5.3.02026-01-30
CVE-2026-21418 [HIGH] CWE-78 CVE-2026-21418: Dell Unity, version(s) 5.5.2 and prior, contain(s) an Improper Neutralization of Special Elements us Dell Unity, version(s) 5.5.2 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary command execution with root privileges.
nvd
CVE-2025-43939P3HIGHCVSS 7.8fixed in 5.5.2.02025-10-30
CVE-2025-43939 [HIGH] CWE-78 CVE-2025-43939: Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution and Elevation of privileges.
nvd
CVE-2025-43940P3HIGHCVSS 7.8fixed in 5.5.2.02025-10-30
CVE-2025-43940 [HIGH] CWE-78 CVE-2025-43940: Dell Unity, version(s) 5.5 and Prior, contain(s) an Improper Neutralization of Special Elements used Dell Unity, version(s) 5.5 and Prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution and Elevation of privileges.
nvd
CVE-2025-43942P3HIGHCVSS 7.8fixed in 5.5.2.02025-10-30
CVE-2025-43942 [HIGH] CWE-78 CVE-2025-43942: Dell Unity, version(s) 5.5 and prior, contain(s) an Improper Neutralization of Special Elements used Dell Unity, version(s) 5.5 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution and Elevation of privileges.
nvd
CVE-2025-36607P3HIGHCVSS 7.8fixed in 5.5.1.02025-08-04
CVE-2025-36607 [HIGH] CWE-78 CVE-2025-36607: Dell Unity, version(s) 5.5 and prior, contain(s) an OS Command Injection Vulnerability in its svc_na Dell Unity, version(s) 5.5 and prior, contain(s) an OS Command Injection Vulnerability in its svc_nas utility. An authenticated attacker could potentially exploit this vulnerability, escaping the restricted shell and execute arbitrary operating system commands with root privileges.
nvd
CVE-2025-36606P3HIGHCVSS 7.8fixed in 5.5.1.02025-08-04
CVE-2025-36606 [HIGH] CWE-78 CVE-2025-36606: Dell Unity, version(s) 5.5 and prior, contain(s) an OS Command Injection Vulnerability in its svc_nf Dell Unity, version(s) 5.5 and prior, contain(s) an OS Command Injection Vulnerability in its svc_nfssupport utility. An authenticated attacker could potentially exploit this vulnerability, escaping the restricted shell and execute arbitrary operating system commands with root privileges.
nvd
CVE-2024-49563P3HIGHCVSS 7.8fixed in 5.5.0.0.5.2592025-03-28
CVE-2024-49563 [HIGH] CWE-78 CVE-2024-49563: Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to execution of arbitrary operating system commands with root privileges and elevation of privileg
nvd
CVE-2024-49564P3HIGHCVSS 7.8fixed in 5.5.0.0.5.2592025-03-28
CVE-2024-49564 [HIGH] CWE-78 CVE-2024-49564: Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to execution of arbitrary operating system commands with root privileges and elevation of privileg
nvd
CVE-2025-24381P3HIGHCVSS 8.8fixed in 5.5.0.0.5.2592025-03-28
CVE-2025-24381 [HIGH] CWE-601 CVE-2025-24381: Dell Unity, version(s) 5.4 and prior, contain(s) an URL Redirection to Untrusted Site ('Open Redirec Dell Unity, version(s) 5.4 and prior, contain(s) an URL Redirection to Untrusted Site ('Open Redirect') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to a targeted application user being redirected to arbitrary web URLs. The vulnerability could be leveraged by attackers to conduct p
nvd
CVE-2024-0168P3HIGHCVSS 7.8fixed in 5.4.0.0.5.0942024-02-12
CVE-2024-0168 [HIGH] CWE-78 CVE-2024-0168: Dell Unity, versions prior to 5.4, contains a Command Injection Vulnerability in svc_oscheck utilit Dell Unity, versions prior to 5.4, contains a Command Injection Vulnerability in svc_oscheck utility. An authenticated attacker could potentially exploit this vulnerability, leading to the ability to inject arbitrary operating system commands. This vulnerability allows an authenticated attacker to execute commands with root privileges.
nvd