VYPR

CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')

ClassDraftLikelihood: High

Description

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-136 · CAPEC-15 · CAPEC-183 · CAPEC-248 · CAPEC-40 · CAPEC-43 · CAPEC-75 · CAPEC-76

CVEs mapped to this weakness (3,835)

page 64 of 192
  • CVE-2024-24301HigFeb 14, 2024
    risk 0.57cvss 8.8epss 0.02

    Command Injection vulnerability discovered in 4ipnet EAP-767 device v3.42.00 within the web interface of the device allows attackers with valid credentials to inject arbitrary shell commands to be executed by the device with root privileges.

  • CVE-2024-22093HigFeb 14, 2024
    risk 0.57cvss 8.7epss 0.01

    When running in appliance mode, an authenticated remote command injection vulnerability exists in an undisclosed iControl REST endpoint on multi-bladed systems. A successful exploit can allow the attacker to cross a security boundary.  Note: Software versions which have reached…

  • CVE-2023-40263HigFeb 8, 2024
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in Atos Unify OpenScape Voice Trace Manager V8 before V8 R0.9.11. It allows authenticated command injection via ftp.

  • CVE-2024-22903HigFeb 2, 2024
    risk 0.57cvss 8.8epss 0.02

    Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the deleteUpdateAPK function.

  • CVE-2024-22900HigFeb 2, 2024
    risk 0.57cvss 8.8epss 0.02

    Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the setNetworkCardInfo function.

  • CVE-2023-48791HigDec 13, 2023
    risk 0.57cvss 8.8epss 0.01

    An improper neutralization of special elements used in a command ('Command Injection') vulnerability [CWE-77] in FortiPortal version 7.2.0, version 7.0.6 and below may allow a remote authenticated attacker with at least R/W permission to execute unauthorized commands via…

  • CVE-2023-47576HigDec 13, 2023
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered in Relyum RELY-PCIe 22.2.1 and RELY-REC 23.1.0 devices, allowing authenticated command injection through the web interface.

  • CVE-2023-49213HigNov 23, 2023
    risk 0.57cvss 8.8epss 0.02

    The API endpoints in Ironman PowerShell Universal 3.0.0 through 4.2.0 allow remote attackers to execute arbitrary commands via crafted HTTP requests if a param block is used, due to invalid sanitization of input strings. The fixed versions are 3.10.2, 4.1.10, and 4.2.1.

  • CVE-2023-43322HigOct 28, 2023
    risk 0.57cvss 8.8epss 0.01

    ZPE Systems, Inc Nodegrid OS v5.0.0 to v5.0.17, v5.2.0 to v5.2.19, v5.4.0 to v5.4.16, v5.6.0 to v5.6.13, v5.8.0 to v5.8.10, and v5.10.0 to v5.10.3 was discovered to contain a command injection vulnerability via the endpoint /v1/system/toolkit/files/.

  • CVE-2023-38193HigOct 21, 2023
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in SuperWebMailer 9.00.0.01710. It allows Remote Code Execution via a crafted sendmail command line.

  • CVE-2023-32632HigOct 11, 2023
    risk 0.57cvss 8.8epss 0.01

    A command execution vulnerability exists in the validate.so diag_ping_start functionality of Yifan YF325 v1.0_20221108. A specially crafted network request can lead to command execution. An attacker can send a network request to trigger this vulnerability.

  • CVE-2023-36415HigOct 10, 2023
    risk 0.57cvss 8.8epss 0.02

    Azure Identity SDK Remote Code Execution Vulnerability

  • CVE-2023-36414HigOct 10, 2023
    risk 0.57cvss 8.8epss 0.02

    Azure Identity SDK Remote Code Execution Vulnerability

  • CVE-2023-45208HigOct 10, 2023
    risk 0.57cvss 8.8epss 0.01

    A command injection in the parsing_xml_stasurvey function inside libcgifunc.so of the D-Link DAP-X1860 repeater 1.00 through 1.01b05-01 allows attackers (within range of the repeater) to run shell commands as root during the setup process of the repeater, via a crafted SSID.…

  • CVE-2023-44827HigOct 10, 2023
    risk 0.57cvss 8.8epss 0.01

    An issue in ZenTao Community Edition v.18.6 and before, ZenTao Biz v.8.6 and before, ZenTao Max v.4.7 and before allows an attacker to execute arbitrary code via a crafted script to the Office Conversion Settings function.

  • CVE-2023-45356HigOct 9, 2023
    risk 0.57cvss 8.8epss 0.01

    Atos Unify OpenScape 4000 Platform V10 R1 before Hotfix V10 R1.42.2 4000 and Manager Platform V10 R1 before Hotfix V10 R1.42.2 allow command injection by an authenticated attacker into the platform operating system, leading to administrative access, via dtb pages of the platform…

  • CVE-2023-45355HigOct 9, 2023
    risk 0.57cvss 8.8epss 0.01

    Atos Unify OpenScape 4000 Platform V10 R1 before Hotfix V10 R1.42.2 and 4000 and Manager Platform V10 R1 before Hotfix V10 R1.42.2 allow command injection by an authenticated attacker into the platform operating system, leading to administrative access via the webservice. This…

  • CVE-2023-45351HigOct 9, 2023
    risk 0.57cvss 8.8epss 0.01

    Atos Unify OpenScape 4000 Assistant V10 R1 before V10 R1.42.1, 4000 Assistant V10 R0, 4000 Manager V10 R1 before V10 R1.42.1, and 4000 Manager V10 R0 allow Authenticated Command Injection via AShbr. This is also known as OSFOURK-24039.

  • CVE-2023-42810CriSep 21, 2023
    risk 0.57cvss 9.8epss 0.02

    systeminformation is a System Information Library for Node.JS. Versions 5.0.0 through 5.21.6 have a SSID Command Injection Vulnerability. The problem was fixed with a parameter check in version 5.21.7. As a workaround, check or sanitize parameter strings that are passed to…

  • CVE-2023-43138HigSep 20, 2023
    risk 0.57cvss 8.8epss 0.02

    TPLINK TL-ER5120G 4.0 2.0.0 Build 210817 Rel.80868n has a command injection vulnerability, when an attacker adds NAPT rules after authentication, and the rule name has an injection point.