CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Description
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-108 · CAPEC-15 · CAPEC-43 · CAPEC-6 · CAPEC-88
CVEs mapped to this weakness (6,524)
page 223 of 327| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-11066 | Hig | 0.47 | 7.2 | 0.02 | Nov 11, 2024 | The D-Link DSL6740C modem has an OS Command Injection vulnerability, allowing remote attackers with administrator privileges to inject and execute arbitrary system commands through the specific web page. | ||
| CVE-2024-11065 | Hig | 0.47 | 7.2 | 0.01 | Nov 11, 2024 | The D-Link DSL6740C modem has an OS Command Injection vulnerability, allowing remote attackers with administrator privileges to inject and execute arbitrary system commands through a specific functionality provided by SSH and Telnet. | ||
| CVE-2024-11064 | Hig | 0.47 | 7.2 | 0.01 | Nov 11, 2024 | The D-Link DSL6740C modem has an OS Command Injection vulnerability, allowing remote attackers with administrator privileges to inject and execute arbitrary system commands through a specific functionality provided by SSH and Telnet. | ||
| CVE-2024-11063 | Hig | 0.47 | 7.2 | 0.01 | Nov 11, 2024 | The D-Link DSL6740C modem has an OS Command Injection vulnerability, allowing remote attackers with administrator privileges to inject and execute arbitrary system commands through a specific functionality provided by SSH and Telnet. | ||
| CVE-2024-11062 | Hig | 0.47 | 7.2 | 0.01 | Nov 11, 2024 | The D-Link DSL6740C modem has an OS Command Injection vulnerability, allowing remote attackers with administrator privileges to inject and execute arbitrary system commands through a specific functionality provided by SSH and Telnet. | ||
| CVE-2024-10653 | Hig | 0.47 | 7.2 | 0.01 | Nov 1, 2024 | IDExpert from CHANGING Information Technology does not properly validate a specific parameter in the administrator interface, allowing remote attackers with administrative privileges to inject and execute OS commands on the server. | ||
| CVE-2024-41153 | Hig | 0.47 | 7.2 | 0.02 | Oct 29, 2024 | Command injection vulnerability in the Edge Computing UI for the TRO600 series radios that allows for the execution of arbitrary system commands. If exploited, an attacker with write access to the web UI can execute commands on the device with root privileges, far more extensive… | ||
| CVE-2024-37845 | Hig | 0.47 | 7.2 | 0.01 | Oct 25, 2024 | MangoOS before 5.2.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the Active Process Command feature. | ||
| CVE-2024-6333 | Hig | 0.47 | 7.2 | 0.01 | Oct 17, 2024 | Authenticated Remote Code Execution in Altalink, Versalink & WorkCentre Products. | ||
| CVE-2024-9139 | — | Hig | 0.47 | 7.2 | 0.01 | Oct 14, 2024 | The affected product permits OS command injection through improperly restricted commands, potentially allowing attackers to execute arbitrary code. | |
| CVE-2024-42503 | Hig | 0.47 | 7.2 | 0.01 | Sep 17, 2024 | Authenticated command execution vulnerability exist in the ArubaOS command line interface (CLI). Successful exploitation of this vulnerabilities result in the ability to run arbitrary commands as a priviledge user on the underlying operating system. | ||
| CVE-2024-42502 | Hig | 0.47 | 7.2 | 0.02 | Sep 17, 2024 | Authenticated command injection vulnerability exists in the ArubaOS command line interface. Successful exploitation of this vulnerability result in the ability to inject shell commands on the underlying operating system. | ||
| CVE-2024-8281 | Hig | 0.47 | 7.2 | 0.01 | Sep 13, 2024 | An input validation weakness was discovered in XCC that could allow a valid, authenticated XCC user with elevated privileges to perform command injection through specially crafted command line input in the XCC SSH captive shell. | ||
| CVE-2024-8280 | Hig | 0.47 | 7.2 | 0.01 | Sep 13, 2024 | An input validation weakness was discovered in XCC that could allow a valid, authenticated XCC user with elevated privileges to perform command injection or cause a recoverable denial of service using a specially crafted file. | ||
| CVE-2024-8279 | Hig | 0.47 | 7.2 | 0.01 | Sep 13, 2024 | A privilege escalation vulnerability was discovered in XCC that could allow a valid, authenticated XCC user with elevated privileges to perform command injection via specially crafted file uploads. | ||
| CVE-2024-8278 | Hig | 0.47 | 7.2 | 0.01 | Sep 13, 2024 | A privilege escalation vulnerability was discovered in XCC that could allow a valid, authenticated XCC user with elevated privileges to perform command injection via specially crafted IPMI commands. | ||
| CVE-2024-8686 | Hig | 0.47 | 7.2 | 0.01 | Sep 11, 2024 | A command injection vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as root on the firewall. | ||
| CVE-2024-20483 | Hig | 0.47 | 7.2 | 0.01 | Sep 11, 2024 | Multiple vulnerabilities in Cisco Routed PON Controller Software, which runs as a docker container on hardware that is supported by Cisco IOS XR Software, could allow an authenticated, remote attacker with Administrator-level privileges on the PON Manager or direct access to the… | ||
| CVE-2023-39300 | Hig | 0.47 | 7.2 | 0.01 | Sep 6, 2024 | An OS command injection vulnerability has been reported to affect legacy QTS. If exploited, the vulnerability could allow authenticated administrators to execute commands via a network. We have already fixed the vulnerability in the following versions: QTS 4.3.6.2805 build… | ||
| CVE-2024-7203 | Hig | 0.47 | 7.2 | 0.01 | Sep 3, 2024 | A post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V4.60 through V5.38 and USG FLEX series firmware versions from V4.60 through V5.38 could allow an authenticated attacker with administrator privileges to execute some operating… |
- risk 0.47cvss 7.2epss 0.02
The D-Link DSL6740C modem has an OS Command Injection vulnerability, allowing remote attackers with administrator privileges to inject and execute arbitrary system commands through the specific web page.
- risk 0.47cvss 7.2epss 0.01
The D-Link DSL6740C modem has an OS Command Injection vulnerability, allowing remote attackers with administrator privileges to inject and execute arbitrary system commands through a specific functionality provided by SSH and Telnet.
- risk 0.47cvss 7.2epss 0.01
The D-Link DSL6740C modem has an OS Command Injection vulnerability, allowing remote attackers with administrator privileges to inject and execute arbitrary system commands through a specific functionality provided by SSH and Telnet.
- risk 0.47cvss 7.2epss 0.01
The D-Link DSL6740C modem has an OS Command Injection vulnerability, allowing remote attackers with administrator privileges to inject and execute arbitrary system commands through a specific functionality provided by SSH and Telnet.
- risk 0.47cvss 7.2epss 0.01
The D-Link DSL6740C modem has an OS Command Injection vulnerability, allowing remote attackers with administrator privileges to inject and execute arbitrary system commands through a specific functionality provided by SSH and Telnet.
- risk 0.47cvss 7.2epss 0.01
IDExpert from CHANGING Information Technology does not properly validate a specific parameter in the administrator interface, allowing remote attackers with administrative privileges to inject and execute OS commands on the server.
- risk 0.47cvss 7.2epss 0.02
Command injection vulnerability in the Edge Computing UI for the TRO600 series radios that allows for the execution of arbitrary system commands. If exploited, an attacker with write access to the web UI can execute commands on the device with root privileges, far more extensive…
- risk 0.47cvss 7.2epss 0.01
MangoOS before 5.2.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the Active Process Command feature.
- risk 0.47cvss 7.2epss 0.01
Authenticated Remote Code Execution in Altalink, Versalink & WorkCentre Products.
- risk 0.47cvss 7.2epss 0.01
The affected product permits OS command injection through improperly restricted commands, potentially allowing attackers to execute arbitrary code.
- risk 0.47cvss 7.2epss 0.01
Authenticated command execution vulnerability exist in the ArubaOS command line interface (CLI). Successful exploitation of this vulnerabilities result in the ability to run arbitrary commands as a priviledge user on the underlying operating system.
- risk 0.47cvss 7.2epss 0.02
Authenticated command injection vulnerability exists in the ArubaOS command line interface. Successful exploitation of this vulnerability result in the ability to inject shell commands on the underlying operating system.
- risk 0.47cvss 7.2epss 0.01
An input validation weakness was discovered in XCC that could allow a valid, authenticated XCC user with elevated privileges to perform command injection through specially crafted command line input in the XCC SSH captive shell.
- risk 0.47cvss 7.2epss 0.01
An input validation weakness was discovered in XCC that could allow a valid, authenticated XCC user with elevated privileges to perform command injection or cause a recoverable denial of service using a specially crafted file.
- risk 0.47cvss 7.2epss 0.01
A privilege escalation vulnerability was discovered in XCC that could allow a valid, authenticated XCC user with elevated privileges to perform command injection via specially crafted file uploads.
- risk 0.47cvss 7.2epss 0.01
A privilege escalation vulnerability was discovered in XCC that could allow a valid, authenticated XCC user with elevated privileges to perform command injection via specially crafted IPMI commands.
- risk 0.47cvss 7.2epss 0.01
A command injection vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as root on the firewall.
- risk 0.47cvss 7.2epss 0.01
Multiple vulnerabilities in Cisco Routed PON Controller Software, which runs as a docker container on hardware that is supported by Cisco IOS XR Software, could allow an authenticated, remote attacker with Administrator-level privileges on the PON Manager or direct access to the…
- risk 0.47cvss 7.2epss 0.01
An OS command injection vulnerability has been reported to affect legacy QTS. If exploited, the vulnerability could allow authenticated administrators to execute commands via a network. We have already fixed the vulnerability in the following versions: QTS 4.3.6.2805 build…
- risk 0.47cvss 7.2epss 0.01
A post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V4.60 through V5.38 and USG FLEX series firmware versions from V4.60 through V5.38 could allow an authenticated attacker with administrator privileges to execute some operating…