CVE-2025-43943

Severity CVSS v4.0:
Pending analysis
Type:
CWE-78 OS Command Injections
Publication date:
25/09/2025
Last modified:
16/01/2026

Description

Dell Cloud Disaster Recovery, version(s) prior to 19.20, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability to execute arbitrary commands with root privileges.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:dell:cloud_disaster_recovery:*:*:*:*:*:*:*:* 19.20 (excluding)