Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Command execution.
CVE ID: CVE-2024-49601
CVSS Base Severity: HIGH
CVSS Base Score: 7.3
CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Vendor: Dell
Product: Unity
EPSS Score: 4.03% (probability of being exploited)
EPSS Percentile: 87.83% (scored less or equal to compared to others)
EPSS Date: 2025-04-25 (when was this score calculated)