DSA-2025-354: Security Update for Dell Cloud Disaster Recovery RCE vulnerability

Summary: Dell Cloud Disaster Recovery remediation is available for RCE vulnerability that could be exploited by malicious users to compromise the affected system.

This article applies to This article does not apply to This article is not tied to any specific product. Not all product versions are identified in this article.

Impact

Medium

Details

Proprietary Code CVEs Description  CVSS Base Score CVSS Vector String 
CVE-2025-43943 Dell Cloud Disaster Recovery, version(s) prior to 19.20, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability to execute arbitrary commands with root privileges. 6.7

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H This hyperlink is taking you to a website outside of Dell Technologies.

Proprietary Code CVEs Description  CVSS Base Score CVSS Vector String 
CVE-2025-43943 Dell Cloud Disaster Recovery, version(s) prior to 19.20, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability to execute arbitrary commands with root privileges. 6.7

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H This hyperlink is taking you to a website outside of Dell Technologies.

Dell Technologies recommends all customers consider both the CVSS base score and any relevant temporal and environmental scores that may impact the potential severity associated with a particular security vulnerability.

Affected Products & Remediation

Product Affected Versions Remediated Versions Link
Dell Cloud Disaster Recovery Versions prior to 19.20 Version 19.20 or later Cloud Disaster Recovery Downloads Area
Product Affected Versions Remediated Versions Link
Dell Cloud Disaster Recovery Versions prior to 19.20 Version 19.20 or later Cloud Disaster Recovery Downloads Area

Revision History

RevisionDateDescription
1.02025-09-23Initial Release
2.02025-09-23Updated Acknowledgements Section
3.02025-09-23Updated for enhanced format presentation with no changes to content

Acknowledgements

Dell would like to thank zzcentury for reporting this issue.

Related Information

Affected Products

Cloud Disaster Recovery
Article Properties
Article Number: 000372457
Article Type: Dell Security Advisory
Last Modified: 23 Sep 2025
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.