CVE-2018-1251: Dell Emc Unity Firmware
High severity, CVSS 8.1. EPSS: 2.5% chance of exploitation in the next 30 days.
Dell EMC Unity and UnityVSA versions prior to 4.3.1.1525703027 contains a URL Redirection vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability to redirect Unity users to arbitrary web URLs by tricking the victim user to click on a maliciously crafted Unisphere URL. Attacker could potentially phish information, including Unisphere users' credentials, from the victim once they are redirected.
Affected products
- Dell Emc Unity Firmware: before 4.3.1.1525703027 (fixed in 4.3.1.1525703027)
- Dell Emc Unityvsa: before 4.3.1.1525703027 (fixed in 4.3.1.1525703027)
Published 2018-09-28. Last modified 2026-06-17.