← Vulnerability feed

Vulnerability record · CVE-2025-22398 · published 28 March 2025

CVE-2025-22398: Dell unity operating environment os command injection vulnerability

Dell · Unity Operating Environment

Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to arbitrary command execution as root. Exploitation may lead to a system take over by an attacker. This vulnerability is considered critical as it can be leveraged to completely compromise the operating system. Dell recommends customers to upgrade at the earliest opportunity.

9.8 CVSS 3.1 Critical EPSS 2.0% · top 19.8% CWE-78 · OS command injection
9.8CVSS 3.1 base score
2.0%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to arbitrary command execution as root. Exploitation may lead to a system take over by an attacker. This vulnerability is considered critical as it can be leveraged to completely compromise the operating system. Dell recommends customers to upgrade at the earliest opportunity.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-22398 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-36604Dell Unity OS Command Injection Allows Unauthenticated Remote Code ExecutionDell Unity versions 5.5 and prior contain an OS command injection flaw (CWE-78) in the Unity Operating Environment. An unauthenticated remote attacke…EPSS 64%analysed9.8CVE-2024-49601Dell unity operating environment os command injection vulnerabilityDell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulner…EPSS 1.5%9.8CVE-2022-29084Dell unity operating environment improper restriction of authentication attempts vulnerabilityDell Unity, Dell UnityVSA, and Dell Unity XT versions before 5.2.0.0.5.173 do not restrict excessive authentication attempts in Unisphere GUI. A remo…EPSS 1.9%9.1CVE-2025-24383Dell unity operating environment os command injection vulnerabilityDell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulner…EPSS 1.1%8.8CVE-2025-24381Dell unity operating environment open redirect vulnerabilityDell Unity, version(s) 5.4 and prior, contain(s) an URL Redirection to Untrusted Site ('Open Redirect') vulnerability. An unauthenticated attacker wi…EPSS 1.4%7.8CVE-2026-22277Dell unity operating environment os command injection vulnerabilityDell UnityVSA, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vul…EPSS 0.66%7.8CVE-2026-21418Dell unity operating environment os command injection vulnerabilityDell Unity, version(s) 5.5.2 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vuln…EPSS 0.66%7.8CVE-2025-43942Dell unity operating environment os command injection vulnerabilityDell Unity, version(s) 5.5 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulner…EPSS 0.59%

Source: NIST National Vulnerability Database (record CVE-2025-22398), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.