ZeroHour

CVE-2025-36604

large

Unauthenticated OS Command Injection in Dell Unity 5.5 and Prior

CVSS 3.1
9.8 critical
EPSS
64%p99
Published
()
Modified
AI analysis

Dell Unity versions 5.5 and prior contain an OS command injection flaw (CWE-78) in which special elements passed to an operating system command are not properly neutralized by the Unity operating environment. An unauthenticated, remote attacker can trigger the flaw by sending crafted input containing shell metacharacters, causing arbitrary commands to execute on the affected system. Successful exploitation gives the attacker command execution with high impact to confidentiality, integrity, and availability, reflected in the critical 9.8 CVSS score. Any organization running a Dell Unity array on version 5.5 or earlier is affected, with practical risk concentrated on arrays whose management interfaces are reachable from untrusted networks. No public proof-of-concept or confirmed in-the-wild exploitation is known yet, but the 63.9% EPSS score (99th percentile) signals a high predicted likelihood of exploitation within 30 days.

What to do: Upgrade affected Unity systems to the fixed release identified in Dell's security advisory for CVE-2025-36604. Until patched, restrict network access to Unity management services to trusted management networks and eliminate any direct internet exposure of the array. Inventory your environment for Unity arrays running version 5.5 or earlier and prioritize internet-facing systems given the high EPSS score.

Affected
Dell Unity Operating Environment (Dell Unity)5.5 and prior
Estimated exposure
large≈10,000–100,000 deployed Unity arrays (version 5.5 and prior spans essentially the entire installed base of this midrange storage line) — Dell Unity is a widely deployed midrange enterprise storage array line with a large installed base, and the affected range covers all versions through 5.5, though only a subset of arrays expose management services to untrusted networks.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Dell Unity, version(s) 5.5 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to arbitrary command execution.

Vendors
dell
Products
unity operating environment
Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news