OS Command Injection Vulnerability in Dell Cloud Disaster Recovery
CVE-2025-43943

6.7MEDIUM

Key Information:

Vendor

Dell

Vendor
CVE Published:
25 September 2025

What is CVE-2025-43943?

The Dell Cloud Disaster Recovery product prior to version 19.20 is vulnerable to an OS command injection that allows high privileged attackers with local access to execute arbitrary commands. This flaw can be exploited to gain root-level execution capabilities, posing a significant risk to system integrity and data security. It is crucial for users to upgrade to the latest version to mitigate this vulnerability effectively.

Affected Version(s)

Cloud Disaster Recovery < 19.20

References

CVSS V3.1

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dell would like to thank zzcentury for reporting this issue.
.
CVE-2025-43943 : OS Command Injection Vulnerability in Dell Cloud Disaster Recovery