VYPR

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-15 · CAPEC-43 · CAPEC-6 · CAPEC-88

CVEs mapped to this weakness (6,573)

page 135 of 329
  • CVE-2024-4301HigApr 29, 2024
    risk 0.57cvss 8.8epss 0.01

    N-Reporter and N-Cloud, products of the N-Partner, have an OS Command Injection vulnerability. Remote attackers with normal user privilege can execute arbitrary system commands by manipulating user inputs on a specific page.

  • CVE-2024-20295HigApr 24, 2024
    risk 0.57cvss 8.8epss 0.01

    A vulnerability in the CLI of the Cisco Integrated Management Controller (IMC) could allow an authenticated, local attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit this vulnerability, the attacker must…

  • CVE-2023-4856HigApr 15, 2024
    risk 0.57cvss 8.8epss 0.01

    A format string vulnerability was identified in SMM/SMM2 and FPC that could allow an authenticated user to execute arbitrary commands on a specific API endpoint.

  • CVE-2024-1655HigApr 15, 2024
    risk 0.57cvss 8.8epss 0.02

    Certain ASUS WiFi routers models has an OS Command Injection vulnerability, allowing an authenticated remote attacker to execute arbitrary system commands by sending a specially crafted request.

  • CVE-2024-2029CriApr 10, 2024
    risk 0.57cvss 9.8epss 0.03

    A command injection vulnerability exists in the `TranscriptEndpoint` of mudler/localai, specifically within the `audioToWav` function used for converting audio files to WAV format for transcription. The vulnerability arises due to the lack of sanitization of user-supplied…

  • CVE-2024-21756HigApr 9, 2024
    risk 0.57cvss 8.8epss 0.02

    A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.3, FortiSandbox 4.2.1 through 4.2.6, FortiSandbox 4.0.0 through 4.0.4 allows attacker to execute unauthorized code or commands…

  • CVE-2024-21755HigApr 9, 2024
    risk 0.57cvss 8.8epss 0.02

    A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.3, FortiSandbox 4.2.1 through 4.2.6, FortiSandbox 4.0.0 through 4.0.4 allows attacker to execute unauthorized code or commands…

  • CVE-2023-1082HigApr 9, 2024
    risk 0.57cvss 8.8epss 0.01

    An remote attacker with low privileges can perform a command injection which can lead to root access.

  • CVE-2024-25568HigApr 4, 2024
    risk 0.57cvss 8.8epss 0.01

    OS command injection vulnerability in ELECOM wireless LAN routers allows a network-adjacent unauthenticated attacker to execute arbitrary OS commands by sending a specially crafted request to the product. Affected products and versions are as follows: WRC-X3200GST3-B v1.25 and…

  • CVE-2024-25002HigMar 25, 2024
    risk 0.57cvss 8.8epss 0.01

    Command Injection in the diagnostics interface of the Bosch Network Synchronizer allows unauthorized users full access to the device.

  • CVE-2024-2162HigMar 21, 2024
    risk 0.57cvss 8.8epss 0.02

    An OS Command Injection vulnerability in Kiloview NDI allows a low-privileged user to execute arbitrary code remotely on the device with high privileges. This issue affects Kiloview NDI N3, N3-s, N4, N20, N30, N40 and was fixed in Firmware version 2.02.0227 .

  • CVE-2024-27772HigMar 18, 2024
    risk 0.57cvss 8.8epss 0.02

    Unitronics Unistream Unilogic – Versions prior to 1.35.227 - CWE-78: 'OS Command Injection' may allow RCE

  • CVE-2024-27516CriFeb 29, 2024
    risk 0.57cvss 9.8epss 0.01

    Server-Side Template Injection (SSTI) vulnerability in livehelperchat before 4.34v, allows remote attackers to execute arbitrary code and obtain sensitive information via the search parameter in lhc_web/modules/lhfaq/faqweight.php.

  • CVE-2024-25626HigFeb 19, 2024
    risk 0.57cvss 8.8epss 0.01

    Yocto Project is an open source collaboration project that helps developers create custom Linux-based systems regardless of the hardware architecture. In Yocto Projects Bitbake before 2.6.2 (before and included Yocto Project 4.3.1), with the Toaster server (included in bitbake)…

  • CVE-2024-23789HigFeb 14, 2024
    risk 0.57cvss 8.8epss 0.01

    Energy Management Controller with Cloud Services JH-RVB1 /JH-RV11 Ver.B0.1.9.1 and earlier allows a network-adjacent unauthenticated attacker to execute an arbitrary OS command on the affected product.

  • CVE-2023-39297HigFeb 2, 2024
    risk 0.57cvss 8.8epss 0.01

    An OS command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated users to execute commands via a network. We have already fixed the vulnerability in the following versions: QTS…

  • CVE-2023-6078HigFeb 1, 2024
    risk 0.57cvss 8.8epss 0.02

    An OS Command Injection vulnerability exists in BIOVIA Materials Studio products from Release BIOVIA 2021 through Release BIOVIA 2023. Upload of a specially crafted perl script can lead to arbitrary command execution.

  • CVE-2023-51217HigJan 18, 2024
    risk 0.57cvss 8.8epss 0.01

    An issue discovered in TenghuTOS TWS-200 firmware version:V4.0-201809201424 allows a remote attacker to execute arbitrary code via crafted command on the ping page component.

  • CVE-2023-49254HigJan 12, 2024
    risk 0.57cvss 8.8epss 0.01

    Authenticated user can execute arbitrary commands in the context of the root user by providing payload in the "destination" field of the network test tools. This is similar to the vulnerability CVE-2021-28151 mitigated on the user interface level by blacklisting characters with…

  • CVE-2024-21833HigJan 11, 2024
    risk 0.57cvss 8.8epss 0.01

    Multiple TP-LINK products allow a network-adjacent unauthenticated attacker with access to the product to execute arbitrary OS commands. The affected device, with the initial configuration, allows login only from the LAN port or Wi-Fi.