VYPR

CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')

ClassDraftLikelihood: High

Description

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-136 · CAPEC-15 · CAPEC-183 · CAPEC-248 · CAPEC-40 · CAPEC-43 · CAPEC-75 · CAPEC-76

CVEs mapped to this weakness (3,816)

page 21 of 191
  • CVE-2024-42509CriNov 5, 2024
    risk 0.64cvss 9.8epss 0.02

    Command injection vulnerability in the underlying CLI service could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port (8211). Successful exploitation of this vulnerability…

  • CVE-2024-10035CriNov 4, 2024
    risk 0.64cvss 9.8epss 0.01

    Improper Control of Generation of Code ('Code Injection'), Improper Neutralization of Special Elements used in a Command ('Command Injection'), Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in BG-TEK Informatics Security…

  • CVE-2024-51260CriOct 31, 2024
    risk 0.64cvss 9.8epss 0.01

    DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the acme_process function.

  • CVE-2024-51255CriOct 31, 2024
    risk 0.64cvss 9.8epss 0.00

    DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the ruequest_certificate function.

  • CVE-2024-51259CriOct 31, 2024
    risk 0.64cvss 9.8epss 0.00

    DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the setup_cacertificate function.

  • CVE-2024-48904CriOct 22, 2024
    risk 0.64cvss 9.8epss 0.02

    An command injection vulnerability in Trend Micro Cloud Edge could allow a remote attacker to execute arbitrary code on affected appliances. Please note: authentication is not required in order to exploit this vulnerability.

  • CVE-2024-35285CriOct 21, 2024
    risk 0.64cvss 9.8epss 0.01

    A vulnerability in NuPoint Messenger (NPM) of Mitel MiCollab through 9.8.0.33 allows an unauthenticated attacker to conduct a command injection attack due to insufficient parameter sanitization.

  • CVE-2024-48659CriOct 21, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue in DCME-320-L <=9.3.2.114 allows a remote attacker to execute arbitrary code via the log_u_umount.php component.

  • CVE-2024-48153CriOct 14, 2024
    risk 0.64cvss 9.8epss 0.01

    DrayTek Vigor3900 1.5.1.3 allows attackers to inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the get_subconfig function.

  • CVE-2024-9380HigKEVOct 8, 2024
    risk 0.64cvss 7.2epss 0.63

    An OS command injection vulnerability in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to obtain remote code execution.

  • CVE-2024-20432CriOct 2, 2024
    risk 0.64cvss 9.9epss 0.01

    A vulnerability in the REST API and web UI of Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an authenticated, low-privileged, remote attacker to perform a command injection attack against an affected device. This vulnerability is due to improper user…

  • CVE-2024-42507CriSep 25, 2024
    risk 0.64cvss 9.8epss 0.01

    Command injection vulnerabilities in the underlying CLI service could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port (8211). Successful exploitation of these…

  • CVE-2024-42506CriSep 25, 2024
    risk 0.64cvss 9.8epss 0.01

    Command injection vulnerabilities in the underlying CLI service could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port (8211). Successful exploitation of these…

  • CVE-2024-42505CriSep 25, 2024
    risk 0.64cvss 9.8epss 0.01

    Command injection vulnerabilities in the underlying CLI service could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's Access Point management protocol) UDP port (8211). Successful exploitation of these…

  • CVE-2024-45824CriSep 12, 2024
    risk 0.64cvss 9.8epss 0.01

    CVE-2024-45824 IMPACT A remote code vulnerability exists in the affected products. The vulnerability occurs when chained with Path Traversal, Command Injection, and XSS Vulnerabilities and allows for full unauthenticated remote code execution. The link in the mitigations…

  • CVE-2023-36103CriSep 10, 2024
    risk 0.64cvss 9.8epss 0.01

    Command Injection vulnerability in goform/SetIPTVCfg interface of Tenda AC15 V15.03.05.20 allows remote attackers to run arbitrary commands via crafted POST request.

  • CVE-2024-44410CriSep 9, 2024
    risk 0.64cvss 9.8epss 0.03

    D-Link DI-8300 v16.07.26A1 is vulnerable to command injection via the upgrade_filter_asp function.

  • CVE-2024-44402CriSep 6, 2024
    risk 0.64cvss 9.8epss 0.03

    D-Link DI-8100G 17.12.20A1 is vulnerable to Command Injection via msp_info.htm.

  • CVE-2024-44401CriSep 6, 2024
    risk 0.64cvss 9.8epss 0.03

    D-Link DI-8100G 17.12.20A1 is vulnerable to Command Injection via sub47A60C function in the upgrade_filter.asp file

  • CVE-2024-8073CriAug 26, 2024
    risk 0.64cvss 9.8epss 0.01

    Improper Input Validation vulnerability in Hillstone Networks Hillstone Networks Web Application Firewall on 5.5R6 allows Command Injection.This issue affects Hillstone Networks Web Application Firewall: from 5.5R6-2.6.7 through 5.5R6-2.8.13.