CVE-2025-36604: OS Command Injection
Dell Unity, version(s) 5.5 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to arbitrary command execution.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36604?
CVE-2025-36604 has a high severity rating due to its potential for arbitrary command execution by unauthenticated attackers.
How do I fix CVE-2025-36604?
To fix CVE-2025-36604, upgrade Dell Unity to version 5.5 or later as recommended by Dell's security advisory.
Who is affected by CVE-2025-36604?
CVE-2025-36604 affects all versions of Dell Unity up to and including version 5.5.
What type of vulnerability is CVE-2025-36604?
CVE-2025-36604 is classified as an OS Command Injection vulnerability due to improper neutralization of special elements.
Can an attacker exploit CVE-2025-36604 remotely?
Yes, an unauthenticated attacker with remote access can potentially exploit CVE-2025-36604.