VYPR

CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')

ClassDraftLikelihood: High

Description

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-136 · CAPEC-15 · CAPEC-183 · CAPEC-248 · CAPEC-40 · CAPEC-43 · CAPEC-75 · CAPEC-76

CVEs mapped to this weakness (3,835)

page 129 of 192
  • CVE-2022-39083MedJan 4, 2023
    risk 0.44cvss 6.7epss 0.00

    In network service, there is a missing permission check. This could lead to local escalation of privilege with System execution privileges needed.

  • CVE-2022-39082MedJan 4, 2023
    risk 0.44cvss 6.7epss 0.00

    In network service, there is a missing permission check. This could lead to local escalation of privilege with System execution privileges needed.

  • CVE-2022-39081MedJan 4, 2023
    risk 0.44cvss 6.7epss 0.00

    In network service, there is a missing permission check. This could lead to local escalation of privilege with System execution privileges needed.

  • CVE-2022-42906HigOct 13, 2022
    risk 0.44cvss 7.8epss 0.00

    powerline-gitstatus (aka Powerline Gitstatus) before 1.3.2 allows arbitrary code execution. git repositories can contain per-repository configuration that changes the behavior of git, including running arbitrary commands. When using powerline-gitstatus, changing to a directory…

  • CVE-2022-32154MedJun 15, 2022
    risk 0.44cvss 6.8epss 0.01

    Dashboards in Splunk Enterprise versions before 9.0 might let an attacker inject risky search commands into a form token when the token is used in a query in a cross-origin request. The result bypasses SPL safeguards for risky commands. See New capabilities can limit access to…

  • CVE-2021-45532MedDec 26, 2021
    risk 0.44cvss 6.7epss 0.01

    NETGEAR R8000 devices before 1.0.4.76 are affected by command injection by an authenticated user.

  • CVE-2021-34729MedSep 23, 2021
    risk 0.44cvss 6.7epss 0.00

    A vulnerability in the CLI of Cisco IOS XE SD-WAN Software and Cisco IOS XE Software could allow an authenticated, local attacker to execute arbitrary commands with elevated privileges on an affected device. This vulnerability is due to insufficient validation of arguments…

  • CVE-2021-34726MedSep 23, 2021
    risk 0.44cvss 6.7epss 0.00

    A vulnerability in the CLI of Cisco SD-WAN Software could allow an authenticated, local attacker to inject arbitrary commands to be executed with root-level privileges on the underlying operating system of an affected device. This vulnerability is due to insufficient input…

  • CVE-2021-34725MedSep 23, 2021
    risk 0.44cvss 6.7epss 0.00

    A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to inject arbitrary commands to be executed with root-level privileges on the underlying operating system. This vulnerability is due to insufficient input validation on…

  • CVE-2021-3515MedJun 1, 2021
    risk 0.44cvss 6.7epss 0.00

    A shell injection flaw was found in pglogical in versions before 2.3.4 and before 3.6.26. An attacker with CREATEDB privileges on a PostgreSQL server can craft a database name that allows execution of shell commands as the postgresql user when calling…

  • CVE-2020-36198MedMay 13, 2021
    risk 0.44cvss 6.7epss 0.01

    A command injection vulnerability has been reported to affect certain versions of Malware Remover. If exploited, this vulnerability allows remote attackers to execute arbitrary commands. This issue affects: QNAP Systems Inc. Malware Remover versions prior to 4.6.1.0. This issue…

  • CVE-2021-1488MedApr 29, 2021
    risk 0.44cvss 6.7epss 0.00

    A vulnerability in the upgrade process of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to inject commands that could be executed with root privileges on the underlying operating…

  • CVE-2020-27867MedFeb 12, 2021
    risk 0.44cvss 6.8epss 0.02

    This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6020, R6080, R6120, R6220, R6260, R6700v2, R6800, R6900v2, R7450, JNR3210, WNR2020, Nighthawk AC2100, and Nighthawk AC2400 routers. Although authentication is…

  • CVE-2021-0364MedFeb 3, 2021
    risk 0.44cvss 6.7epss 0.00

    In mobile_log_d, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-10, Android-11;…

  • CVE-2021-0363MedFeb 3, 2021
    risk 0.44cvss 6.7epss 0.00

    In mobile_log_d, there is a possible command injection due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-10, Android-11;…

  • CVE-2021-0358MedFeb 3, 2021
    risk 0.44cvss 6.7epss 0.00

    In netdiag, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-10, Android-11;…

  • CVE-2021-0356MedFeb 3, 2021
    risk 0.44cvss 6.7epss 0.00

    In netdiag, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-10, Android-11;…

  • CVE-2020-9127MedNov 13, 2020
    risk 0.44cvss 6.7epss 0.00

    Some Huawei products have a command injection vulnerability. Due to insufficient input validation, an attacker with high privilege may inject some malicious codes in some files of the affected products. Successful exploit may cause command injection.Affected product versions…

  • CVE-2020-11496MedOct 19, 2020
    risk 0.44cvss 6.7epss 0.00

    Sprecher SPRECON-E firmware prior to 8.64b might allow local attackers with access to engineering data to insert arbitrary code. This firmware lacks the validation of the input values on the device side, which is provided by the engineering software during parameterization.…

  • CVE-2020-26914MedOct 9, 2020
    risk 0.44cvss 6.7epss 0.01

    Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D6200 before 1.1.00.38, D7000 before 1.0.1.78, JR6150 before 1.0.1.24, R6020 before 1.0.0.42, R6050 before 1.0.1.24, R6080 before 1.0.0.42, R6120 before 1.0.0.66, R6220 before…