Dell Technologies has released a security advisory detailing multiple critical vulnerabilities in its Dell Unity storage systems and related software.
These vulnerabilities, if exploited, could allow attackers to gain unauthorized access, execute arbitrary commands, or even compromise the affected systems entirely.
The advisory, issued under reference DSA-2025-116, highlights serious weaknesses in Dell Unity, UnityVSA, and Unity XT platforms, including their operating environment (OE).
These vulnerabilities affect versions before 5.5.0.0.5.259 and stem from several issues such as improper neutralization of special elements in system commands, open redirect flaws, and OS command injection vulnerabilities.
Key CVEs Identified
Dell has acknowledged the contributions of security researchers, including teams from Ubisectech Sirius, who reported many of these vulnerabilities.
The vulnerabilities have been classified as critical, with high CVSS scores ranging from 7.3 to 9.8. Exploitation risks include:
Given the severity, these flaws pose a significant risk to enterprises relying on Dell Unity systems for their storage solutions.
Dell has released version 5.5.0.0.5.259 of the Unity Operating Environment (OE) to address these vulnerabilities. Customers are strongly advised to upgrade immediately to mitigate risks.
Organizations using Dell Unity solutions should prioritize this patch to secure their infrastructures and prevent potential attacks.
Dell credited independent researchers, including Prowser and the Ubisectech Sirius Team, for their contributions in identifying these vulnerabilities.
The company recommends that customers assess the applicability of these findings to their environments and take swift action.
Dell has reiterated its commitment to strengthening security in its products through collaboration with the cybersecurity community.
Find this News Interesting! Follow us on Google News, LinkedIn, and X to Get Instant Updates
!
Brinker, an innovative narrative intelligence platform dedicated to combating disinformation and influence campaigns, has been…
A recent investigation by cybersecurity researchers has uncovered a large-scale malware campaign leveraging the DeepSeek…
A recent malware campaign has been observed targeting the First Ukrainian International Bank (PUMB), utilizing…
A newly discovered malware, dubbed Trojan.Arcanum, is targeting enthusiasts of tarot, astrology, and other esoteric…
A sophisticated phishing campaign orchestrated by a Russian-speaking threat actor has been uncovered, revealing the…
A sophisticated malware campaign has compromised over 1,500 PostgreSQL servers, leveraging fileless techniques to deploy…