CVE-2025-24377
Description
Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution and Elevation of privileges.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A local low-privileged attacker can inject OS commands in Dell Unity versions 5.4 and prior, leading to code execution and privilege escalation.
Vulnerability
The vulnerability is an OS command injection (CWE-78) in Dell Unity, Dell UnityVSA, and Dell Unity XT systems running versions 5.4 and prior [1]. An attacker can inject arbitrary operating system commands through improperly neutralized special elements within the application's input processing. No specific configuration or special conditions beyond local access are mentioned in the references.
Exploitation
An attacker with low privileges and local access to the Dell Unity system can exploit this vulnerability. The exact steps are not detailed in the available references, but the attacker likely sends crafted input to a vulnerable interface that passes the input unsanitized to a system shell [1]. No user interaction or race window is required other than having valid low-privileged credentials and local access.
Impact
Successful exploitation allows the attacker to execute arbitrary operating system commands with elevated privileges. This leads to full compromise of the system: code execution and elevation of privileges from a low-privileged user to a higher privilege level, potentially administrative [1]. The confidentiality, integrity, and availability of the affected system are all at risk.
Mitigation
Dell has released a security update to address this vulnerability. The fix is included in the update documented in DSA-2025-116 [1]. Organizations should apply the recommended update as soon as possible. No workaround is provided. The product is not listed as EOL or on the CISA KEV catalog based on the references.
AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.