MEDIUM✓ PATCH🇵🇱 Wersja polska

CVE-2025-43943

CVSS 6.7v3.1pub. 2025-09-25upd. 2026-01-16

Dell Cloud Disaster Recovery, version(s) prior to 19.20, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability to execute arbitrary commands with root privileges.

CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
  • Dell Cloud Disaster Recovery

    APP
    Dell
    < 19.20
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
Command Injection
CWE
References

Related vulnerabilities

CVE-2026-70419CRITICAL9.1same product

Dell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements ...

CVE-2026-71171HIGH7.2same product

Dell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements ...

CVE-2026-71172MEDIUM4.3same product

Dell Cloud Disaster Recovery, versions 20.2 and prior, contain a Server-Side Request Forgery (SSRF) vulnerabil...

CVE-2026-22769CRITICAL10.0⚠ KEVPL ✓same vendor

Dell RecoverPoint for VMs — zahardkodowane dane uwierzytelniające (RCE, root)

CVE-2026-54489CRITICAL9.1PL ✓same vendor

Dell Virtual Storage Integrator — ujawnienie sesji i przejęcie konta