CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Description
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-15 · CAPEC-43 · CAPEC-6 · CAPEC-88
CVEs mapped to this weakness (6,578)
page 180 of 329| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-26217 | Hig | 0.52 | 8.0 | 0.85 | Nov 16, 2020 | XStream before version 1.4.14 is vulnerable to Remote Code Execution.The vulnerability may allow a remote attacker to run arbitrary shell commands only by manipulating the processed input stream. Only users who rely on blocklists are affected. Anyone using XStream's Security… | ||
| CVE-2020-15631 | Hig | 0.52 | 8.0 | 0.03 | Jul 23, 2020 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-1860 1.04B03_HOTFIX WiFi extenders. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed.… | ||
| CVE-2019-14894 | Hig | 0.52 | 8.0 | 0.04 | Jun 22, 2020 | A flaw was found in the CloudForms management engine version 5.10 and CloudForms management version 5.11, which triggered remote code execution through NFS schedule backup. An attacker logged into the management console could use this flaw to execute arbitrary shell commands on… | ||
| CVE-2018-21100 | Hig | 0.52 | 8.0 | 0.01 | Apr 27, 2020 | NETGEAR R7800 devices before 1.0.2.60 are affected by command injection by an authenticated user. | ||
| CVE-2018-21099 | Hig | 0.52 | 8.0 | 0.01 | Apr 27, 2020 | NETGEAR R7800 devices before 1.0.2.60 are affected by command injection by an authenticated user. | ||
| CVE-2018-21101 | Hig | 0.52 | 8.0 | 0.01 | Apr 23, 2020 | NETGEAR R7800 devices before 1.0.2.60 are affected by command injection by an authenticated user. | ||
| CVE-2020-5350 | Hig | 0.52 | 7.9 | 0.02 | Apr 15, 2020 | Dell EMC Integrated Data Protection Appliance versions 2.0, 2.1, 2.2, 2.3, 2.4 contain a command injection vulnerability in the ACM component. A remote authenticated malicious user with root privileges could inject parameters in the ACM component APIs that could lead to… | ||
| CVE-2020-5534 | Hig | 0.52 | 8.0 | 0.01 | Feb 21, 2020 | Aterm WG2600HS firmware Ver1.3.2 and earlier allows an authenticated attacker on the same network segment to execute arbitrary OS commands with root privileges via unspecified vectors. | ||
| CVE-2020-5525 | Hig | 0.52 | 8.0 | 0.01 | Feb 21, 2020 | Aterm series (Aterm WF1200C firmware Ver1.2.1 and earlier, Aterm WG1200CR firmware Ver1.2.1 and earlier, Aterm WG2600HS firmware Ver1.3.2 and earlier) allows an authenticated attacker on the same network segment to execute arbitrary OS commands with root privileges via… | ||
| CVE-2020-8947 | Hig | 0.52 | 7.2 | 0.22 | Feb 12, 2020 | functions_netflow.php in Artica Pandora FMS 7.0 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the index.php?operation/netflow/nf_live_view ip_dst, dst_port, or src_port parameter, a different vulnerability than CVE-2019-20224. | ||
| CVE-2019-18909 | Hig | 0.52 | 8.0 | 0.02 | Nov 22, 2019 | The VPN software within HP ThinPro does not safely handle user supplied input, which may be leveraged by an attacker to inject commands that will execute with root privileges. | ||
| CVE-2019-10392 | Hig | 0.52 | 8.8 | 0.26 | Sep 12, 2019 | Jenkins Git Client Plugin 2.8.4 and earlier and 3.0.0-rc did not properly restrict values passed as URL argument to an invocation of 'git ls-remote', resulting in OS command injection. | ||
| CVE-2019-14260 | Hig | 0.52 | 8.0 | 0.03 | Aug 1, 2019 | On the Alcatel-Lucent Enterprise (ALE) 8008 Cloud Edition Deskphone VoIP phone with firmware 1.50.13, a command injection (missing input validation) issue in the password change field for the Change Password interface allows an authenticated remote attacker in the same network… | ||
| CVE-2019-14259 | Hig | 0.52 | 8.0 | 0.03 | Aug 1, 2019 | On the Polycom Obihai Obi1022 VoIP phone with firmware 5.1.11, a command injection (missing input validation) issue in the NTP server IP address field for the "Time Service Settings web" interface allows an authenticated remote attacker in the same network to trigger OS commands… | ||
| CVE-2019-9156 | Hig | 0.52 | 8.0 | 0.03 | Jun 5, 2019 | Gemalto DS3 Authentication Server 2.6.1-SP01 allows OS Command Injection. | ||
| CVE-2018-19977 | Hig | 0.52 | 8.0 | 0.04 | May 29, 2019 | A command injection (missing input validation, escaping) in the ftp upgrade configuration interface on the Auerswald COMfort 1200 IP phone 3.4.4.1-10589 allows an authenticated remote attacker (simple user) -- in the same network as the device -- to trigger OS commands (like… | ||
| CVE-2018-16216 | Hig | 0.52 | 8.0 | 0.04 | Apr 25, 2019 | A command injection (missing input validation, escaping) in the monitoring or memory status web interface in AudioCodes 405HD (firmware 2.2.12) VoIP phone allows an authenticated remote attacker in the same network as the device to trigger OS commands (like starting telnetd or… | ||
| CVE-2018-3910 | Hig | 0.52 | 8.0 | 0.02 | Nov 1, 2018 | An exploitable code execution vulnerability exists in the cloud OTA setup functionality of Yi Home Camera 27US 1.8.7.0D. A specially crafted SSID can cause a command injection, resulting in code execution. An attacker can cause a camera to connect to this SSID to trigger this… | ||
| CVE-2017-2183 | Hig | 0.52 | 8.0 | 0.01 | Jul 7, 2017 | HOME SPOT CUBE2 firmware V101 and earlier allows authenticated attackers to execute arbitrary OS commands via Clock Settings. | ||
| CVE-2015-8557 | Cri | 0.52 | 9.0 | 0.07 | Jan 8, 2016 | The FontManager._get_nix_font_path function in formatters/img.py in Pygments 1.2.2 through 2.0.2 allows remote attackers to execute arbitrary commands via shell metacharacters in a font name. |
- risk 0.52cvss 8.0epss 0.85
XStream before version 1.4.14 is vulnerable to Remote Code Execution.The vulnerability may allow a remote attacker to run arbitrary shell commands only by manipulating the processed input stream. Only users who rely on blocklists are affected. Anyone using XStream's Security…
- risk 0.52cvss 8.0epss 0.03
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DAP-1860 1.04B03_HOTFIX WiFi extenders. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed.…
- risk 0.52cvss 8.0epss 0.04
A flaw was found in the CloudForms management engine version 5.10 and CloudForms management version 5.11, which triggered remote code execution through NFS schedule backup. An attacker logged into the management console could use this flaw to execute arbitrary shell commands on…
- risk 0.52cvss 8.0epss 0.01
NETGEAR R7800 devices before 1.0.2.60 are affected by command injection by an authenticated user.
- risk 0.52cvss 8.0epss 0.01
NETGEAR R7800 devices before 1.0.2.60 are affected by command injection by an authenticated user.
- risk 0.52cvss 8.0epss 0.01
NETGEAR R7800 devices before 1.0.2.60 are affected by command injection by an authenticated user.
- risk 0.52cvss 7.9epss 0.02
Dell EMC Integrated Data Protection Appliance versions 2.0, 2.1, 2.2, 2.3, 2.4 contain a command injection vulnerability in the ACM component. A remote authenticated malicious user with root privileges could inject parameters in the ACM component APIs that could lead to…
- risk 0.52cvss 8.0epss 0.01
Aterm WG2600HS firmware Ver1.3.2 and earlier allows an authenticated attacker on the same network segment to execute arbitrary OS commands with root privileges via unspecified vectors.
- risk 0.52cvss 8.0epss 0.01
Aterm series (Aterm WF1200C firmware Ver1.2.1 and earlier, Aterm WG1200CR firmware Ver1.2.1 and earlier, Aterm WG2600HS firmware Ver1.3.2 and earlier) allows an authenticated attacker on the same network segment to execute arbitrary OS commands with root privileges via…
- risk 0.52cvss 7.2epss 0.22
functions_netflow.php in Artica Pandora FMS 7.0 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the index.php?operation/netflow/nf_live_view ip_dst, dst_port, or src_port parameter, a different vulnerability than CVE-2019-20224.
- risk 0.52cvss 8.0epss 0.02
The VPN software within HP ThinPro does not safely handle user supplied input, which may be leveraged by an attacker to inject commands that will execute with root privileges.
- risk 0.52cvss 8.8epss 0.26
Jenkins Git Client Plugin 2.8.4 and earlier and 3.0.0-rc did not properly restrict values passed as URL argument to an invocation of 'git ls-remote', resulting in OS command injection.
- risk 0.52cvss 8.0epss 0.03
On the Alcatel-Lucent Enterprise (ALE) 8008 Cloud Edition Deskphone VoIP phone with firmware 1.50.13, a command injection (missing input validation) issue in the password change field for the Change Password interface allows an authenticated remote attacker in the same network…
- risk 0.52cvss 8.0epss 0.03
On the Polycom Obihai Obi1022 VoIP phone with firmware 5.1.11, a command injection (missing input validation) issue in the NTP server IP address field for the "Time Service Settings web" interface allows an authenticated remote attacker in the same network to trigger OS commands…
- risk 0.52cvss 8.0epss 0.03
Gemalto DS3 Authentication Server 2.6.1-SP01 allows OS Command Injection.
- risk 0.52cvss 8.0epss 0.04
A command injection (missing input validation, escaping) in the ftp upgrade configuration interface on the Auerswald COMfort 1200 IP phone 3.4.4.1-10589 allows an authenticated remote attacker (simple user) -- in the same network as the device -- to trigger OS commands (like…
- risk 0.52cvss 8.0epss 0.04
A command injection (missing input validation, escaping) in the monitoring or memory status web interface in AudioCodes 405HD (firmware 2.2.12) VoIP phone allows an authenticated remote attacker in the same network as the device to trigger OS commands (like starting telnetd or…
- risk 0.52cvss 8.0epss 0.02
An exploitable code execution vulnerability exists in the cloud OTA setup functionality of Yi Home Camera 27US 1.8.7.0D. A specially crafted SSID can cause a command injection, resulting in code execution. An attacker can cause a camera to connect to this SSID to trigger this…
- risk 0.52cvss 8.0epss 0.01
HOME SPOT CUBE2 firmware V101 and earlier allows authenticated attackers to execute arbitrary OS commands via Clock Settings.
- risk 0.52cvss 9.0epss 0.07
The FontManager._get_nix_font_path function in formatters/img.py in Pygments 1.2.2 through 2.0.2 allows remote attackers to execute arbitrary commands via shell metacharacters in a font name.