CVE-2025-36606

HIGH

Dell Unity Operating Environment < 5.5.1.0 - Authenticated OS Command Injection via svc_nfssupport Utility

Title source: llm
STIX 2.1

Description

Dell Unity, version(s) 5.5 and prior, contain(s) an OS Command Injection Vulnerability in its svc_nfssupport utility. An authenticated attacker could potentially exploit this vulnerability, escaping the restricted shell and execute arbitrary operating system commands with root privileges.

Scores

CVSS v3 7.8
EPSS 0.0005
EPSS Percentile 16.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-78
Status published
Products (1)
dell/unity_operating_environment < 5.5.1.0
Published Aug 04, 2025
Tracked Since Feb 18, 2026