CVE-2025-43941: OS Command Injection
Dell Unity, version(s) 5.5 and Prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability to execute arbitrary command with root privileges. This vulnerability only affects systems without a valid license install.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Install a valid license on Dell Unity systems, as the vulnerability only affects systems without a valid license installed.
Event History
Frequently Asked Questions
What is the severity of CVE-2025-43941?
CVE-2025-43941 is classified as a low-severity vulnerability that allows command injection with local access.
How do I fix CVE-2025-43941?
To remediate CVE-2025-43941, update your Dell Unity software to a version newer than 5.5.
Who is affected by CVE-2025-43941?
CVE-2025-43941 affects users of Dell Unity versions 5.5 and prior.
What type of vulnerability is CVE-2025-43941?
CVE-2025-43941 is an OS Command Injection vulnerability allowing arbitrary command execution.
Can a remote attacker exploit CVE-2025-43941?
No, CVE-2025-43941 requires local access for exploitation.