VYPR

CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')

ClassDraftLikelihood: High

Description

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-136 · CAPEC-15 · CAPEC-183 · CAPEC-248 · CAPEC-40 · CAPEC-43 · CAPEC-75 · CAPEC-76

CVEs mapped to this weakness (3,835)

page 88 of 192
  • CVE-2019-20761HigApr 16, 2020
    risk 0.52cvss 8.0epss 0.02

    NETGEAR R7800 devices before 1.0.2.62 are affected by command injection by an authenticated user.

  • CVE-2019-20711HigApr 16, 2020
    risk 0.52cvss 8.0epss 0.01

    Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.76, D6000 before 1.0.0.76, and XR500 before 2.3.2.32.

  • CVE-2019-20710HigApr 16, 2020
    risk 0.52cvss 8.0epss 0.01

    Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.76, D6000 before 1.0.0.76, and XR500 before 2.3.2.32.

  • CVE-2019-20709HigApr 16, 2020
    risk 0.52cvss 8.0epss 0.01

    Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.76, D6000 before 1.0.0.76, and XR500 before 2.3.2.32.

  • CVE-2019-20708HigApr 16, 2020
    risk 0.52cvss 8.0epss 0.01

    Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.76, D6000 before 1.0.0.76, and XR500 before 2.3.2.32.

  • CVE-2019-20707HigApr 16, 2020
    risk 0.52cvss 8.0epss 0.01

    Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R7800 before 1.0.2.60 and XR500 before 2.3.2.32.

  • CVE-2019-20706HigApr 16, 2020
    risk 0.52cvss 8.0epss 0.02

    Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R7800 before 1.0.2.60 and XR500 before 2.3.2.32.

  • CVE-2019-20705HigApr 16, 2020
    risk 0.52cvss 8.0epss 0.01

    Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.76, D6000 before 1.0.0.76, and XR500 before 2.3.2.32.

  • CVE-2019-20704HigApr 16, 2020
    risk 0.52cvss 8.0epss 0.01

    Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.76, D6000 before 1.0.0.76, and XR500 before 2.3.2.32.

  • CVE-2019-20703HigApr 16, 2020
    risk 0.52cvss 8.0epss 0.01

    Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.76, D6000 before 1.0.0.76, and XR500 before 2.3.2.32.

  • CVE-2019-20702HigApr 16, 2020
    risk 0.52cvss 8.0epss 0.01

    Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.76, D6000 before 1.0.0.76, and XR500 before 2.3.2.32.

  • CVE-2019-20701HigApr 16, 2020
    risk 0.52cvss 8.0epss 0.01

    Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D3600 before 1.0.0.76, D6000 before 1.0.0.76, and XR500 before 2.3.2.32.

  • CVE-2019-20680HigApr 15, 2020
    risk 0.52cvss 8.0epss 0.01

    Certain NETGEAR devices are affected by command injection by an authenticated user. This affects D7000v2 before 1.0.0.53, R6220 before 1.1.0.80, R6260 before 1.1.0.64, R6700 before 1.0.2.6, R6700v2 before 1.2.0.36, R6800 before 1.2.0.36, R6900 before 1.0.2.4, R6900P before…

  • CVE-2019-3421HigOct 31, 2019
    risk 0.52cvss 8.0epss 0.01

    The 7520V3V1.0.0B09P27 version, and all earlier versions of ZTE product ZX297520V3 are impacted by a Command Injection vulnerability. Unauthorized users can exploit this vulnerability to control the user terminal system.

  • CVE-2019-7610CriMar 25, 2019
    risk 0.52cvss 9.0epss 0.04

    Kibana versions before 6.6.1 contain an arbitrary code execution flaw in the security audit logger. If a Kibana instance has the setting xpack.security.audit.enabled set to true, an attacker could send a request that will attempt to execute javascript code. This could possibly…

  • CVE-2018-3963HigMar 21, 2019
    risk 0.52cvss 8.0epss 0.03

    An exploitable command injection vulnerability exists in the DHCP daemon configuration of the CUJO Smart Firewall. When adding a new static DHCP address, its corresponding hostname is inserted into the dhcpd.conf file without prior sanitization, allowing for arbitrary execution…

  • CVE-2017-8193HigNov 22, 2017
    risk 0.52cvss 8.0epss 0.01

    The FusionSphere OpenStack V100R006C00SPC102(NFV) has a command injection vulnerability. Due to the insufficient input validation on one port, an authenticated, local attacker may exploit the vulnerability to gain root privileges by sending message with malicious commands.

  • CVE-2016-9554HigJan 28, 2017
    risk 0.52cvss 7.2epss 0.25

    The Sophos Web Appliance Remote / Secure Web Gateway server (version 4.2.1.3) is vulnerable to a Remote Command Injection vulnerability in its web administrative interface. These vulnerabilities occur in MgrDiagnosticTools.php (/controllers/MgrDiagnosticTools.php), in the…

  • CVE-2016-4822HigJun 25, 2016
    risk 0.52cvss 8.0epss 0.01

    Corega CG-WLBARGL devices allow remote authenticated users to execute arbitrary commands via unspecified vectors.

  • CVE-1999-0039HigMay 6, 1997
    risk 0.52cvss 7.3epss 0.16

    webdist CGI program (webdist.cgi) in SGI IRIX allows remote attackers to execute arbitrary commands via shell metacharacters in the distloc parameter.