VYPR

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-15 · CAPEC-43 · CAPEC-6 · CAPEC-88

CVEs mapped to this weakness (6,578)

page 190 of 329
  • CVE-2022-22454HigMay 10, 2022
    risk 0.51cvss 7.8epss 0.00

    IBM InfoSphere Information Server 11.7 could allow a locally authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request.

  • CVE-2022-27188HigApr 15, 2022
    risk 0.51cvss 7.8epss 0.01

    OS command injection vulnerability exists in CENTUM VP R4.01.00 to R4.03.00, CENTUM VP Small R4.01.00 to R4.03.00, CENTUM VP Basic R4.01.00 to R4.03.00, and B/M9000 VP R6.01.01 to R6.03.02, which may allow an attacker who can access the computer where the affected product is…

  • CVE-2022-1262HigApr 11, 2022
    risk 0.51cvss 7.8epss 0.02

    A command injection vulnerability in the protest binary allows an attacker with access to the remote command line interface to execute arbitrary commands as root.

  • CVE-2021-26104HigApr 6, 2022
    risk 0.51cvss 7.8epss 0.03

    Multiple OS command injection (CWE-78) vulnerabilities in the command line interface of FortiManager 6.2.7 and below, 6.4.5 and below and all versions of 6.2.x, 6.0.x and 5.6.x, FortiAnalyzer 6.2.7 and below, 6.4.5 and below and all versions of 6.2.x, 6.0.x and 5.6.x, and…

  • CVE-2022-22301HigMar 2, 2022
    risk 0.51cvss 7.8epss 0.00

    An improper neutralization of special elements used in an OS Command vulnerability [CWE-78] in FortiAP-C console 5.4.0 through 5.4.3, 5.2.0 through 5.2.1 may allow an authenticated attacker to execute unauthorized commands by running CLI commands with specifically crafted…

  • CVE-2022-22945HigFeb 16, 2022
    risk 0.51cvss 7.8epss 0.00

    VMware NSX Edge contains a CLI shell injection vulnerability. A malicious actor with SSH access to an NSX-Edge appliance can execute arbitrary commands on the operating system as root.

  • CVE-2021-26616HigFeb 9, 2022
    risk 0.51cvss 7.8epss 0.01

    An OS command injection was found in SecuwaySSL, when special characters injection on execute command with runCommand arguments.

  • CVE-2021-41016HigFeb 2, 2022
    risk 0.51cvss 7.8epss 0.01

    A improper neutralization of special elements used in a command ('command injection') in Fortinet FortiExtender version 7.0.1 and below, 4.2.3 and below, 4.1.7 and below allows an authenticated attacker to execute privileged shell commands via CLI commands including special…

  • CVE-2021-45844HigJan 25, 2022
    risk 0.51cvss 7.8epss 0.01

    Improper sanitization in the invocation of ODA File Converter from FreeCAD 0.19 allows an attacker to inject OS commands via a crafted filename.

  • CVE-2022-22991HigJan 13, 2022
    risk 0.51cvss 7.8epss 0.01

    A malicious user on the same LAN could use DNS spoofing followed by a command injection attack to trick a NAS device into loading through an unsecured HTTP call. Addressed this vulnerability by disabling checks for internet connectivity using HTTP.

  • CVE-2021-45912HigJan 4, 2022
    risk 0.51cvss 7.8epss 0.00

    An unauthenticated Named Pipe channel in Controlup Real-Time Agent (cuAgent.exe) before 8.5 potentially allows an attacker to run OS commands via the ProcessActionRequest WCF method.

  • CVE-2021-45979HigJan 4, 2022
    risk 0.51cvss 7.8epss 0.02

    Foxit PDF Reader and PDF Editor before 11.1 on macOS allow remote attackers to execute arbitrary code via app.launchURL in the JavaScript API.

  • CVE-2021-45978HigJan 4, 2022
    risk 0.51cvss 7.8epss 0.01

    Foxit PDF Reader and PDF Editor before 11.1 on macOS allow remote attackers to execute arbitrary code via xfa.host.gotoURL in the XFA API.

  • CVE-2021-1529HigOct 21, 2021
    risk 0.51cvss 7.8epss 0.00

    A vulnerability in the CLI of Cisco IOS XE SD-WAN Software could allow an authenticated, local attacker to execute arbitrary commands with root privileges. The vulnerability is due to insufficient input validation by the system CLI. An attacker could exploit this vulnerability…

  • CVE-2021-31358HigOct 19, 2021
    risk 0.51cvss 7.8epss 0.01

    A command injection vulnerability in sftp command processing on Juniper Networks Junos OS Evolved allows an attacker with authenticated CLI access to be able to bypass configured access protections to execute arbitrary shell commands within the context of the current user. The…

  • CVE-2021-31357HigOct 19, 2021
    risk 0.51cvss 7.8epss 0.01

    A command injection vulnerability in tcpdump command processing on Juniper Networks Junos OS Evolved allows an attacker with authenticated CLI access to be able to bypass configured access protections to execute arbitrary shell commands within the context of the current user.…

  • CVE-2021-31356HigOct 19, 2021
    risk 0.51cvss 7.8epss 0.01

    A command injection vulnerability in command processing on Juniper Networks Junos OS Evolved allows an attacker with authenticated CLI access to be able to bypass configured access protections to execute arbitrary shell commands within the context of the current user. The…

  • CVE-2021-34728HigSep 9, 2021
    risk 0.51cvss 7.8epss 0.00

    Multiple vulnerabilities in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker with a low-privileged account to elevate privileges on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.

  • CVE-2021-34719HigSep 9, 2021
    risk 0.51cvss 7.8epss 0.00

    Multiple vulnerabilities in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker with a low-privileged account to elevate privileges on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.

  • CVE-2021-26106HigJul 9, 2021
    risk 0.51cvss 7.8epss 0.00

    An improper neutralization of special elements used in an OS Command vulnerability in FortiAP's console 6.4.1 through 6.4.5 and 6.2.4 through 6.2.5 may allow an authenticated attacker to execute unauthorized commands by running the kdbg CLI command with specifically crafted…