← Vulnerability feed

Vulnerability record · CVE-2025-43940 · published 30 October 2025

CVE-2025-43940: Dell unity operating environment os command injection vulnerability

Dell · Unity Operating Environment

Dell Unity, version(s) 5.5 and Prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution and Elevation of privileges.

7.8 CVSS 3.1 High EPSS 0.59% · top 54.0% CWE-78 · OS command injection
7.8CVSS 3.1 base score
0.59%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

Dell Unity, version(s) 5.5 and Prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution and Elevation of privileges.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-43940 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-36604Dell Unity OS Command Injection Allows Unauthenticated Remote Code ExecutionDell Unity versions 5.5 and prior contain an OS command injection flaw (CWE-78) in the Unity Operating Environment. An unauthenticated remote attacke…EPSS 64%analysed9.8CVE-2024-49601Dell unity operating environment os command injection vulnerabilityDell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulner…EPSS 1.5%9.8CVE-2025-22398Dell unity operating environment os command injection vulnerabilityDell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulner…EPSS 2.0%9.8CVE-2022-29084Dell unity operating environment improper restriction of authentication attempts vulnerabilityDell Unity, Dell UnityVSA, and Dell Unity XT versions before 5.2.0.0.5.173 do not restrict excessive authentication attempts in Unisphere GUI. A remo…EPSS 1.9%9.1CVE-2025-24383Dell unity operating environment os command injection vulnerabilityDell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulner…EPSS 1.1%8.8CVE-2025-24381Dell unity operating environment open redirect vulnerabilityDell Unity, version(s) 5.4 and prior, contain(s) an URL Redirection to Untrusted Site ('Open Redirect') vulnerability. An unauthenticated attacker wi…EPSS 1.4%7.8CVE-2026-22277Dell unity operating environment os command injection vulnerabilityDell UnityVSA, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vul…EPSS 0.62%7.8CVE-2026-21418Dell unity operating environment os command injection vulnerabilityDell Unity, version(s) 5.5.2 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vuln…EPSS 0.62%

Source: NIST National Vulnerability Database (record CVE-2025-43940), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.