CVE-2024-22228: Dell Unity Operating Environment

High severity, CVSS 7.8. EPSS: 0.6% chance of exploitation in the next 30 days.

Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_cifssupport utility. An authenticated attacker could potentially exploit this vulnerability, escaping the restricted shell and execute arbitrary operating system commands with root privileges.

Affected products

  • Dell Unity Operating Environment: before 5.4.0.0.5.094 (fixed in 5.4.0.0.5.094)

Published 2024-02-12. Last modified 2026-06-17.