VYPR

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-15 · CAPEC-43 · CAPEC-6 · CAPEC-88

CVEs mapped to this weakness (6,578)

page 186 of 329
  • CVE-2024-24890HigMar 25, 2024
    risk 0.51cvss 7.8epss 0.01

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in openEuler gala-gopher on Linux allows Command Injection. This vulnerability is associated with program files https://gitee.Com/openeuler/gala-gopher/blob/master/src/probes/…

  • CVE-2024-2415HigMar 13, 2024
    risk 0.51cvss 7.8epss 0.01

    Command injection vulnerability in Movistar 4G router affecting version ES_WLD71-T1_v2.0.201820. This vulnerability allows an authenticated user to execute commands inside the router by making a POST request to the URL '/cgi-bin/gui.cgi'.

  • CVE-2024-22228HigFeb 12, 2024
    risk 0.51cvss 7.8epss 0.01

    Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_cifssupport utility. An authenticated attacker could potentially exploit this vulnerability, escaping the restricted shell and execute arbitrary operating system commands with root…

  • CVE-2024-22227HigFeb 12, 2024
    risk 0.51cvss 7.8epss 0.01

    Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_dc utility. An authenticated attacker could potentially exploit this vulnerability, leading to the ability execute commands with root privileges.

  • CVE-2024-22225HigFeb 12, 2024
    risk 0.51cvss 7.8epss 0.01

    Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_supportassist utility. An authenticated attacker could potentially exploit this vulnerability, leading to execution of arbitrary operating system commands with root privileges.

  • CVE-2024-22224HigFeb 12, 2024
    risk 0.51cvss 7.8epss 0.01

    Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_nas utility. An authenticated attacker could potentially exploit this vulnerability, escaping the restricted shell and execute arbitrary operating system commands with root privileges.

  • CVE-2024-22223HigFeb 12, 2024
    risk 0.51cvss 7.8epss 0.01

    Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability within its svc_cbr utility. An authenticated malicious user with local access could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's…

  • CVE-2024-22222HigFeb 12, 2024
    risk 0.51cvss 7.8epss 0.01

    Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability within its svc_udoctor utility. An authenticated malicious user with local access could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the…

  • CVE-2024-0170HigFeb 12, 2024
    risk 0.51cvss 7.8epss 0.01

    Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_cava utility. An authenticated attacker could potentially exploit this vulnerability, escaping the restricted shell and execute arbitrary operating system commands with root privileges.…

  • CVE-2024-0168HigFeb 12, 2024
    risk 0.51cvss 7.8epss 0.01

    Dell Unity, versions prior to 5.4, contains a Command Injection Vulnerability in svc_oscheck utility. An authenticated attacker could potentially exploit this vulnerability, leading to the ability to inject arbitrary operating system commands. This vulnerability allows an…

  • CVE-2024-0167HigFeb 12, 2024
    risk 0.51cvss 7.8epss 0.01

    Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in the svc_topstats utility. An authenticated attacker could potentially exploit this vulnerability, leading to the ability to overwrite arbitrary files on the file system with root privileges.

  • CVE-2024-0166HigFeb 12, 2024
    risk 0.51cvss 7.8epss 0.01

    Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_tcpdump utility. An authenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands with elevated privileges.

  • CVE-2024-0165HigFeb 12, 2024
    risk 0.51cvss 7.8epss 0.01

    Dell Unity, versions prior to 5.4, contains an OS Command Injection Vulnerability in its svc_acldb_dump utility. An authenticated attacker could potentially exploit this vulnerability, leading to execution of arbitrary operating system commands with root privileges.

  • CVE-2024-0164HigFeb 12, 2024
    risk 0.51cvss 7.8epss 0.01

    Dell Unity, versions prior to 5.4, contain an OS Command Injection Vulnerability in its svc_topstats utility. An authenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary commands with elevated privileges.

  • CVE-2023-35964HigJan 8, 2024
    risk 0.51cvss 7.8epss 0.01

    Multiple OS command injection vulnerabilities exist in the decompression functionality of GTKWave 3.3.115. A specially crafted wave file can lead to arbitrary command execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability…

  • CVE-2023-35963HigJan 8, 2024
    risk 0.51cvss 7.8epss 0.01

    Multiple OS command injection vulnerabilities exist in the decompression functionality of GTKWave 3.3.115. A specially crafted wave file can lead to arbitrary command execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability…

  • CVE-2023-35962HigJan 8, 2024
    risk 0.51cvss 7.8epss 0.01

    Multiple OS command injection vulnerabilities exist in the decompression functionality of GTKWave 3.3.115. A specially crafted wave file can lead to arbitrary command execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability…

  • CVE-2023-35961HigJan 8, 2024
    risk 0.51cvss 7.8epss 0.01

    Multiple OS command injection vulnerabilities exist in the decompression functionality of GTKWave 3.3.115. A specially crafted wave file can lead to arbitrary command execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability…

  • CVE-2023-35960HigJan 8, 2024
    risk 0.51cvss 7.8epss 0.01

    Multiple OS command injection vulnerabilities exist in the decompression functionality of GTKWave 3.3.115. A specially crafted wave file can lead to arbitrary command execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability…

  • CVE-2023-35959HigJan 8, 2024
    risk 0.51cvss 7.8epss 0.01

    Multiple OS command injection vulnerabilities exist in the decompression functionality of GTKWave 3.3.115. A specially crafted wave file can lead to arbitrary command execution. A victim would need to open a malicious file to trigger these vulnerabilities.This vulnerability…