CVE-2025-36604
largeUnauthenticated OS Command Injection in Dell Unity 5.5 and Prior
Dell Unity versions 5.5 and prior contain an OS command injection flaw (CWE-78) in which special elements passed to an operating system command are not properly neutralized by the Unity operating environment. An unauthenticated, remote attacker can trigger the flaw by sending crafted input containing shell metacharacters, causing arbitrary commands to execute on the affected system. Successful exploitation gives the attacker command execution with high impact to confidentiality, integrity, and availability, reflected in the critical 9.8 CVSS score. Any organization running a Dell Unity array on version 5.5 or earlier is affected, with practical risk concentrated on arrays whose management interfaces are reachable from untrusted networks. No public proof-of-concept or confirmed in-the-wild exploitation is known yet, but the 63.9% EPSS score (99th percentile) signals a high predicted likelihood of exploitation within 30 days.
What to do: Upgrade affected Unity systems to the fixed release identified in Dell's security advisory for CVE-2025-36604. Until patched, restrict network access to Unity management services to trusted management networks and eliminate any direct internet exposure of the array. Inventory your environment for Unity arrays running version 5.5 or earlier and prioritize internet-facing systems given the high EPSS score.
| Dell Unity Operating Environment (Dell Unity) | 5.5 and prior |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Dell Unity, version(s) 5.5 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to arbitrary command execution.
- Vendors
- dell
- Products
- unity operating environment
- Weakness
- CWE-78
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H