VYPR
Unrated severityNVD Advisory· Published Feb 12, 2024· Updated May 6, 2025

CVE-2024-0167

CVE-2024-0167

Description

Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in the svc_topstats utility. An authenticated attacker could potentially exploit this vulnerability, leading to the ability to overwrite arbitrary files on the file system with root privileges.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Dell Unity versions prior to 5.4 are vulnerable to OS command injection in svc_topstats, allowing authenticated attackers to overwrite arbitrary files as root.

Vulnerability

CVE-2024-0167 is an OS command injection vulnerability in the svc_topstats utility of Dell Unity, Dell Unity VSA, and Dell Unity XT storage systems. All versions prior to 5.4 are affected. The flaw resides in how the utility processes user-supplied input when constructing OS commands, allowing an authenticated user to inject arbitrary commands. [1]

Exploitation

An attacker must have authenticated access to the affected Dell Unity system. No special privileges beyond standard user authentication are required. The attacker can then invoke the svc_topstats utility with crafted input that includes command injection payloads, which the utility passes unsanitized to the operating system for execution. [1]

Impact

Successful exploitation allows the attacker to execute arbitrary OS commands with root privileges. This can lead to overwriting arbitrary files on the file system, compromising the confidentiality, integrity, and availability of the storage system. [1]

Mitigation

Dell has released a security update (version 5.4 or later) that addresses this vulnerability. Users should upgrade to Dell Unity OE version 5.4 or later as soon as possible. There are no workarounds disclosed in the available references. [1]

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.