DSA-2026-211 -: Security Update for Dell Unity, Dell UnityVSA and Dell Unity XT Security Update for Multiple Vulnerabilities

Summary: Dell UnityVSA and Dell Unity XT remediation is available for multiple security vulnerabilities that could be exploited by malicious users to compromise the affected system.

This article applies to This article does not apply to This article is not tied to any specific product. Not all product versions are identified in this article.

Impact

High

Details

Third-party Component CVEs More Information
OpenSSL CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796 https://nvd.nist.gov/vuln/search

Proprietary Code CVEs Description CVSS Base Score CVSS Vector String
CVE-2026-32659 Dell Unity, version(s) 5.5.2 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution and Elevation of privileges. 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CVE-2026-32660 Dell UnityVSA, version(s) 5.5.3 and prior, contain(s) an Observable Discrepancy vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information exposure. 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVE-2026-32795 Dell Unity, version(s) 5.5 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution and Elevation of privileges. 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVE-2026-32796 Dell Unity, version(s) 5.5.3 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary command execution with root privileges. 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CVE-2026-32797 Dell Unity, version(s) 5.5.3 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution and Information disclosure. 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVE-2026-32798 Dell Unity, version(s) 5.5.3 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary command execution with root privileges. 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVE-2026-32799 Dell UnityVSA, version(s) 5.5.3 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution and Elevation of privileges. 6.8 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
CVE-2026-32800 Dell UnityVSA, version(s) 5.5.3 and prior, contain(s) an Improper Neutralization of Special Elements vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution. 3.6 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
CVE-2026-32801 Dell UnityVSA, version(s) 5.5.3 and prior, contain(s) an Improper Control of Generation of Code ('Code Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to unauthorized command execution. 6.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Proprietary Code CVEs Description CVSS Base Score CVSS Vector String
CVE-2026-32659 Dell Unity, version(s) 5.5.2 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution and Elevation of privileges. 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CVE-2026-32660 Dell UnityVSA, version(s) 5.5.3 and prior, contain(s) an Observable Discrepancy vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information exposure. 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVE-2026-32795 Dell Unity, version(s) 5.5 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution and Elevation of privileges. 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVE-2026-32796 Dell Unity, version(s) 5.5.3 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary command execution with root privileges. 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CVE-2026-32797 Dell Unity, version(s) 5.5.3 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution and Information disclosure. 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVE-2026-32798 Dell Unity, version(s) 5.5.3 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary command execution with root privileges. 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVE-2026-32799 Dell UnityVSA, version(s) 5.5.3 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution and Elevation of privileges. 6.8 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
CVE-2026-32800 Dell UnityVSA, version(s) 5.5.3 and prior, contain(s) an Improper Neutralization of Special Elements vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Command execution. 3.6 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
CVE-2026-32801 Dell UnityVSA, version(s) 5.5.3 and prior, contain(s) an Improper Control of Generation of Code ('Code Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to unauthorized command execution. 6.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Dell Technologies recommends all customers consider both the CVSS base score and any relevant temporal and environmental scores that may impact the potential severity associated with a particular security vulnerability.

Affected Products & Remediation

CVEs Addressed Product Software/Firmware Affected Versions Remediated Versions Link
CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796, CVE-2026-32659, CVE-2026-32660, CVE-2026-32795, CVE-2026-32796, CVE-2026-32797, CVE-2026-32798, CVE-2026-32799, CVE-2026-32800, CVE-2026-32801 Dell Unity Dell Unity Operating Environment (OE) Versions prior to 5.5.4 5.5.4.0.5.037 https://www.dell.com/support/home/en-us/product-support/product/unity-all-flash-family/drivers
CVEs Addressed Product Software/Firmware Affected Versions Remediated Versions Link
CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69420, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796, CVE-2026-32659, CVE-2026-32660, CVE-2026-32795, CVE-2026-32796, CVE-2026-32797, CVE-2026-32798, CVE-2026-32799, CVE-2026-32800, CVE-2026-32801 Dell Unity Dell Unity Operating Environment (OE) Versions prior to 5.5.4 5.5.4.0.5.037 https://www.dell.com/support/home/en-us/product-support/product/unity-all-flash-family/drivers

Revision History

RevisionDateDescription
1.02025-05-29Initial Release

Related Information

Affected Products

Dell EMC Unity XT 380, Dell EMC Unity XT 480, Dell EMC Unity XT 680, Dell EMC Unity XT 880, Dell Unity Operating Environment (OE)
Article Properties
Article Number: 000470814
Article Type: Dell Security Advisory
Last Modified: 29 مايو 2026
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.