OS Command Injection Vulnerability in Dell Unity Storage Solutions
CVE-2025-36604

7.3HIGH

Key Information:

Vendor

Dell

Status
Vendor
CVE Published:
4 August 2025

What is CVE-2025-36604?

Dell Unity storage solutions, specifically version 5.5 and earlier, are susceptible to an OS Command Injection vulnerability. This security issue could allow an unauthenticated remote attacker to execute arbitrary commands on the underlying operating system. Organizations using affected versions should take immediate action to mitigate the risk and secure their systems. For detailed guidance and remediation steps, refer to the vendor's advisory.

Affected Version(s)

Unity < 5.5.1

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dell would like to thank Sina Kheirkhah of watchTowr for reporting this issue.
.
CVE-2025-36604 : OS Command Injection Vulnerability in Dell Unity Storage Solutions