URL Redirection Vulnerability in Dell Unity by Dell
CVE-2025-24381

8.8HIGH

Key Information:

Vendor
Dell
Status
Vendor
CVE Published:
28 March 2025

Summary

Dell Unity, specifically versions 5.4 and earlier, is susceptible to an Open Redirect vulnerability that allows unauthenticated remote attackers to redirect users to potentially harmful websites. This flaw can be exploited to facilitate phishing attacks, tricking users into providing sensitive information. Additionally, it poses a risk for session theft, allowing unauthorized access to user sessions. Organizations using affected versions should take immediate steps to mitigate this vulnerability to safeguard their systems.

Affected Version(s)

Unity < 5.5.0.0.5.259

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dell would like to thank prowser for reporting these issues.
.