CVE-2025-24379
Description
Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution and Elevation of privileges.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A low-privileged attacker with local access can exploit OS command injection in Dell Unity 5.4 and prior to gain command execution and elevate privileges.
Vulnerability
Dell Unity, UnityVSA, and Unity XT running version 5.4 and prior contain an OS command injection vulnerability (CVE-2025-24379) in the product's management interface. The software fails to properly neutralize special elements used in OS commands, allowing an attacker to inject arbitrary commands into a system call. Affected versions are those prior to the security update released in DSA-2025-116 [1].
Exploitation
An attacker must have low-privileged local access to the Dell Unity system, meaning they already possess a valid account with minimal permissions on the appliance. No additional network-based authentication is required beyond local shell or UI access. The attacker can craft input containing shell metacharacters that are passed unsanitized to an OS command, which then executes with elevated privileges. The exact sequence of steps is not detailed in the available references, but the vulnerability class is a standard OS command injection [1].
Impact
Successful exploitation allows the attacker to execute arbitrary OS commands on the underlying system, leading to full command execution and elevation of privileges. This can result in complete compromise of the Unity storage appliance, including unauthorized access to stored data, disruption of storage services, and potential pivot to other systems on the network. The impact is rated Critical by Dell [1].
Mitigation
Dell has released a security update as part of DSA-2025-116. The advisory recommends upgrading to a fixed version of Dell Unity OE (Operating Environment). The specific fixed version number is not provided in the available reference, but customers should apply the latest Unity OE update from Dell's support site. No workaround is documented; applying the patch is the only mitigation. There is no indication that this CVE is listed in the Known Exploited Vulnerabilities (KEV) catalog at this time.
AI Insight generated on May 24, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.