CVE-2024-22228: Dell Unity Operating Environment
High severity, CVSS 7.8. EPSS: 0.6% chance of exploitation in the next 30 days.
Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_cifssupport utility. An authenticated attacker could potentially exploit this vulnerability, escaping the restricted shell and execute arbitrary operating system commands with root privileges.
Affected products
- Dell Unity Operating Environment: before 5.4.0.0.5.094 (fixed in 5.4.0.0.5.094)
Published 2024-02-12. Last modified 2026-06-17.