CVE-2025-43939: OS Command Injection
Published Oct 30, 2025
·Updated
Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution and Elevation of privileges.
Affected Software
2 affected components
Dell Unity<5.4
Dell Unity Operating Environment<5.5.2.0
Event History
Oct 30, 2025
CVE Published
via MITRE·02:10 PM
Data Sourced
via MITRE·02:10 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-43939?
CVE-2025-43939 is classified as a medium severity vulnerability.
2
How do I fix CVE-2025-43939?
To fix CVE-2025-43939, upgrade to Dell Unity version 5.5 or later.
3
What is the potential impact of CVE-2025-43939?
The potential impact of CVE-2025-43939 includes command execution and privilege escalation by a low privileged attacker.
4
What are the affected versions for CVE-2025-43939?
CVE-2025-43939 affects Dell Unity versions 5.4 and prior.
5
Who can exploit CVE-2025-43939?
A low privileged attacker with local access can exploit CVE-2025-43939.