CVE-2018-1251: Dell Emc Unity Firmware

High severity, CVSS 8.1. EPSS: 2.5% chance of exploitation in the next 30 days.

Dell EMC Unity and UnityVSA versions prior to 4.3.1.1525703027 contains a URL Redirection vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability to redirect Unity users to arbitrary web URLs by tricking the victim user to click on a maliciously crafted Unisphere URL. Attacker could potentially phish information, including Unisphere users' credentials, from the victim once they are redirected.

Affected products

  • Dell Emc Unity Firmware: before 4.3.1.1525703027 (fixed in 4.3.1.1525703027)
  • Dell Emc Unityvsa: before 4.3.1.1525703027 (fixed in 4.3.1.1525703027)

Published 2018-09-28. Last modified 2026-06-17.