VYPR

CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')

ClassDraftLikelihood: High

Description

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-136 · CAPEC-15 · CAPEC-183 · CAPEC-248 · CAPEC-40 · CAPEC-43 · CAPEC-75 · CAPEC-76

CVEs mapped to this weakness (3,835)

page 122 of 192
  • CVE-2020-9116HigDec 1, 2020
    risk 0.47cvss 7.2epss 0.01

    Huawei FusionCompute versions 6.5.1 and 8.0.0 have a command injection vulnerability. An authenticated, remote attacker can craft specific request to exploit this vulnerability. Due to insufficient verification, this could be exploited to cause the attackers to obtain higher…

  • CVE-2020-9115HigDec 1, 2020
    risk 0.47cvss 7.2epss 0.01

    ManageOne versions 6.5.1.1.B010, 6.5.1.1.B020, 6.5.1.1.B030, 6.5.1.1.B040, ,6.5.1.1.B050, 8.0.0 and 8.0.1 have a command injection vulnerability. An attacker with high privileges may exploit this vulnerability through some operations on the plug-in component. Due to insufficient…

  • CVE-2020-2492HigNov 16, 2020
    risk 0.47cvss 7.2epss 0.02

    If exploited, the command injection vulnerability could allow remote attackers to execute arbitrary commands. This issue affects: QNAP Systems Inc. QTS versions prior to 4.4.3.1421 on build 20200907.

  • CVE-2020-2490HigNov 16, 2020
    risk 0.47cvss 7.2epss 0.02

    If exploited, the command injection vulnerability could allow remote attackers to execute arbitrary commands. This issue affects: QNAP Systems Inc. QTS versions prior to 4.4.3.1421 on build 20200907.

  • CVE-2020-4636HigOct 16, 2020
    risk 0.47cvss 7.2epss 0.01

    IBM Resilient OnPrem 38.2 could allow a privileged user to inject malicious commands through Python3 scripting. IBM X-Force ID: 185503.

  • CVE-2020-3279HigJun 18, 2020
    risk 0.47cvss 7.2epss 0.03

    Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Series Routers and Cisco Small Business RV016, RV042, and RV082 Routers could allow an authenticated, remote attacker with administrative privileges to execute arbitrary…

  • CVE-2020-3278HigJun 18, 2020
    risk 0.47cvss 7.2epss 0.03

    Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Series Routers and Cisco Small Business RV016, RV042, and RV082 Routers could allow an authenticated, remote attacker with administrative privileges to execute arbitrary…

  • CVE-2020-3277HigJun 18, 2020
    risk 0.47cvss 7.2epss 0.03

    Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Series Routers and Cisco Small Business RV016, RV042, and RV082 Routers could allow an authenticated, remote attacker with administrative privileges to execute arbitrary…

  • CVE-2020-3276HigJun 18, 2020
    risk 0.47cvss 7.2epss 0.03

    Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Series Routers and Cisco Small Business RV016, RV042, and RV082 Routers could allow an authenticated, remote attacker with administrative privileges to execute arbitrary…

  • CVE-2020-3275HigJun 18, 2020
    risk 0.47cvss 7.2epss 0.03

    Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Series Routers and Cisco Small Business RV016, RV042, and RV082 Routers could allow an authenticated, remote attacker with administrative privileges to execute arbitrary…

  • CVE-2020-3274HigJun 18, 2020
    risk 0.47cvss 7.2epss 0.03

    Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Series Routers and Cisco Small Business RV016, RV042, and RV082 Routers could allow an authenticated, remote attacker with administrative privileges to execute arbitrary…

  • CVE-2020-3212HigJun 3, 2020
    risk 0.47cvss 7.2epss 0.03

    A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system of an affected device. The vulnerability is due to improper input sanitization. An attacker…

  • CVE-2020-3211HigJun 3, 2020
    risk 0.47cvss 7.2epss 0.04

    A vulnerability in the web UI of Cisco IOS XE Software could allow an authenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system of an affected device. The vulnerability is due to improper input sanitization. An attacker…

  • CVE-2019-20659HigApr 15, 2020
    risk 0.47cvss 7.2epss 0.02

    Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R6400v2 before 1.0.4.84, R6700 before 1.0.2.8, R6700v3 before 1.0.4.84, R6900 before 1.0.2.8, and R7900 before 1.0.3.10.

  • CVE-2019-5323HigFeb 27, 2020
    risk 0.47cvss 7.2epss 0.03

    There are command injection vulnerabilities present in the AirWave application. Certain input fields controlled by an administrative user are not properly sanitized before being parsed by AirWave. If conditions are met, an attacker can obtain command execution on the host.

  • CVE-2019-16005HigJan 26, 2020
    risk 0.47cvss 7.2epss 0.04

    A vulnerability in the web-based management interface of Cisco Webex Video Mesh could allow an authenticated, remote attacker to execute arbitrary commands on the affected system. The vulnerability is due to improper validation of user-supplied input by the web-based management…

  • CVE-2019-12629HigJan 26, 2020
    risk 0.47cvss 7.2epss 0.02

    A vulnerability in the WebUI of the Cisco SD-WAN Solution could allow an authenticated, remote attacker to inject and execute arbitrary commands with vmanage user privileges on an affected system. The vulnerability is due to insufficient input validation of data parameters for…

  • CVE-2019-18647HigNov 14, 2019
    risk 0.47cvss 7.2epss 0.02

    The Untangle NG firewall 14.2.0 is vulnerable to an authenticated command injection when logged in as an admin user.

  • CVE-2019-15588HigNov 1, 2019
    risk 0.47cvss 7.2epss 0.06

    There is an OS Command Injection in Nexus Repository Manager <= 2.14.14 (bypass CVE-2019-5475) that could allow an attacker a Remote Code Execution (RCE). All instances using CommandLineExecutor.java with user-supplied data is vulnerable, such as the Yum Configuration Capability.

  • CVE-2019-5446HigJul 10, 2019
    risk 0.47cvss 7.2epss 0.03

    Command Injection in EdgeMAX EdgeSwitch prior to 1.8.2 allow an Admin user to execute commands as root.