VYPR

CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')

ClassDraftLikelihood: High

Description

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-136 · CAPEC-15 · CAPEC-183 · CAPEC-248 · CAPEC-40 · CAPEC-43 · CAPEC-75 · CAPEC-76

CVEs mapped to this weakness (3,835)

page 115 of 192
  • CVE-2024-44916HigAug 30, 2024
    risk 0.47cvss 7.2epss 0.01

    Vulnerability in admin_ip.php in Seacms v13.1, when action=set, allows attackers to control IP parameters that are written to the data/admin/ip.php file and could result in arbitrary command execution.

  • CVE-2024-42636HigAug 23, 2024
    risk 0.47cvss 7.2epss 0.01

    DedeCMS V5.7.115 has a command execution vulnerability via file_manage_view.php?fmdo=newfile&activepath.

  • CVE-2024-21880HigAug 12, 2024
    risk 0.47cvss 7.2epss 0.02

    Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability via the url parameter of an authenticated enpoint in Enphase IQ Gateway (formerly known as Enphase) allows OS Command Injection.This issue affects Envoy: 4.x <= 7.x

  • CVE-2024-3659HigAug 8, 2024
    risk 0.47cvss 7.2epss 0.02

    Firmware in KAON AR2140 routers, prior to versions 3.2.50 and 4.2.16, is vulnerable to a shell command injection via sending a crafted request to one of the endpoints. In order to exploit this vulnerability, one has to have access to the administrative portal of the router.

  • CVE-2022-4002HigJul 31, 2024
    risk 0.47cvss 7.2epss 0.01

    A command injection vulnerability could allow an authenticated user to execute operating system commands as root via a specially crafted API request.

  • CVE-2024-41637HigJul 29, 2024
    risk 0.47cvss 8.3epss 0.01

    RaspAP before 3.1.5 allows an attacker to escalate privileges: the www-data user has write access to the restapi.service file and also possesses Sudo privileges to execute several critical commands without a password.

  • CVE-2024-38288HigJul 25, 2024
    risk 0.47cvss 7.2epss 0.03

    A command-injection issue in the Certificate Signing Request (CSR) functionality in R-HUB TurboMeeting through 8.x allows authenticated attackers with administrator privileges to execute arbitrary commands on the underlying server as root.

  • CVE-2024-41135HigJul 24, 2024
    risk 0.47cvss 7.2epss 0.01

    A vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN gateway's Command Line Interface that allows remote authenticated users to run arbitrary commands on the underlying host. Successful exploitation of this vulnerability will result in the ability to execute…

  • CVE-2024-41134HigJul 24, 2024
    risk 0.47cvss 7.2epss 0.01

    A vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN gateway's Command Line Interface that allows remote authenticated users to run arbitrary commands on the underlying host. Successful exploitation of this vulnerability will result in the ability to execute…

  • CVE-2024-41133HigJul 24, 2024
    risk 0.47cvss 7.2epss 0.01

    A vulnerability exists in the HPE Aruba Networking EdgeConnect SD-WAN gateway's Command Line Interface that allows remote authenticated users to run arbitrary commands on the underlying host. Successful exploitation of this vulnerability will result in the ability to execute…

  • CVE-2024-36073HigJun 27, 2024
    risk 0.47cvss 7.2epss 0.01

    Netwrix CoSoSys Endpoint Protector through 5.9.3 and CoSoSys Unify through 7.0.6 contain a remote code execution vulnerability in the shadowing component of the Endpoint Protector and Unify agent which allows an attacker with administrative access to the Endpoint Protector or…

  • CVE-2024-39373HigJun 27, 2024
    risk 0.47cvss 7.2epss 0.01

    TELSAT marKoni FM Transmitters are vulnerable to a command injection vulnerability through the manipulation of settings and could allow an attacker to gain unauthorized access to the system with administrative privileges.

  • CVE-2023-6321HigMay 15, 2024
    risk 0.47cvss 7.2epss 0.03

    A command injection vulnerability exists in the IOCTL that manages OTA updates. A specially crafted command can lead to command execution as the root user. An attacker can make authenticated requests to trigger this vulnerability.

  • CVE-2024-31485HigMay 14, 2024
    risk 0.47cvss 7.2epss 0.02

    A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V5.30), SICORE Base system (All versions < V1.3.0). The web interface of affected devices is vulnerable to command injection due to missing server side input sanitation. This could…

  • CVE-2024-34338HigMay 14, 2024
    risk 0.47cvss 7.2epss 0.03

    Tenda O3V2 with firmware versions V1.0.0.10 and V1.0.0.12 was discovered to contain a Blind Command Injection via dest parameter in /goform/getTraceroute. This vulnerability allows attackers to execute arbitrary commands with root privileges. Authentication is required to…

  • CVE-2024-34347HigMay 8, 2024
    risk 0.47cvss 8.3epss 0.01

    @hoppscotch/cli is a CLI to run Hoppscotch Test Scripts in CI environments. Prior to 0.8.0, the @hoppscotch/js-sandbox package provides a Javascript sandbox that uses the Node.js vm module. However, the vm module is not safe for sandboxing untrusted Javascript code. This is…

  • CVE-2024-21322HigApr 9, 2024
    risk 0.47cvss 7.2epss 0.03

    Microsoft Defender for IoT Remote Code Execution Vulnerability

  • CVE-2024-29949HigApr 2, 2024
    risk 0.47cvss 7.2epss 0.01

    There is a command injection vulnerability in some Hikvision NVRs. This could allow an authenticated user with administrative rights to execute arbitrary commands.

  • CVE-2024-25955HigMar 28, 2024
    risk 0.47cvss 7.2epss 0.01

    Dell vApp Manager, versions prior to 9.2.4.9 contain a Command Injection Vulnerability. An authorized attacker could potentially exploit this vulnerability leading to an execution of an inserted command. Dell recommends customers to upgrade at the earliest opportunity.

  • CVE-2024-25946HigMar 28, 2024
    risk 0.47cvss 7.2epss 0.01

    Dell vApp Manager, versions prior to 9.2.4.9 contain a Command Injection Vulnerability. An authorized attacker could potentially exploit this vulnerability leading to an execution of an inserted command. Dell recommends customers to upgrade at the earliest opportunity.