VYPR

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-15 · CAPEC-43 · CAPEC-6 · CAPEC-88

CVEs mapped to this weakness (6,524)

page 223 of 327
  • CVE-2024-11066HigNov 11, 2024
    risk 0.47cvss 7.2epss 0.02

    The D-Link DSL6740C modem has an OS Command Injection vulnerability, allowing remote attackers with administrator privileges to inject and execute arbitrary system commands through the specific web page.

  • CVE-2024-11065HigNov 11, 2024
    risk 0.47cvss 7.2epss 0.01

    The D-Link DSL6740C modem has an OS Command Injection vulnerability, allowing remote attackers with administrator privileges to inject and execute arbitrary system commands through a specific functionality provided by SSH and Telnet.

  • CVE-2024-11064HigNov 11, 2024
    risk 0.47cvss 7.2epss 0.01

    The D-Link DSL6740C modem has an OS Command Injection vulnerability, allowing remote attackers with administrator privileges to inject and execute arbitrary system commands through a specific functionality provided by SSH and Telnet.

  • CVE-2024-11063HigNov 11, 2024
    risk 0.47cvss 7.2epss 0.01

    The D-Link DSL6740C modem has an OS Command Injection vulnerability, allowing remote attackers with administrator privileges to inject and execute arbitrary system commands through a specific functionality provided by SSH and Telnet.

  • CVE-2024-11062HigNov 11, 2024
    risk 0.47cvss 7.2epss 0.01

    The D-Link DSL6740C modem has an OS Command Injection vulnerability, allowing remote attackers with administrator privileges to inject and execute arbitrary system commands through a specific functionality provided by SSH and Telnet.

  • CVE-2024-10653HigNov 1, 2024
    risk 0.47cvss 7.2epss 0.01

    IDExpert from CHANGING Information Technology does not properly validate a specific parameter in the administrator interface, allowing remote attackers with administrative privileges to inject and execute OS commands on the server.

  • CVE-2024-41153HigOct 29, 2024
    risk 0.47cvss 7.2epss 0.02

    Command injection vulnerability in the Edge Computing UI for the TRO600 series radios that allows for the execution of arbitrary system commands. If exploited, an attacker with write access to the web UI can execute commands on the device with root privileges, far more extensive…

  • CVE-2024-37845HigOct 25, 2024
    risk 0.47cvss 7.2epss 0.01

    MangoOS before 5.2.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the Active Process Command feature.

  • CVE-2024-6333HigOct 17, 2024
    risk 0.47cvss 7.2epss 0.01

    Authenticated Remote Code Execution in Altalink, Versalink & WorkCentre Products.

  • CVE-2024-9139HigOct 14, 2024
    risk 0.47cvss 7.2epss 0.01

    The affected product permits OS command injection through improperly restricted commands, potentially allowing attackers to execute arbitrary code.

  • CVE-2024-42503HigSep 17, 2024
    risk 0.47cvss 7.2epss 0.01

    Authenticated command execution vulnerability exist in the ArubaOS command line interface (CLI). Successful exploitation of this vulnerabilities result in the ability to run arbitrary commands as a priviledge user on the underlying operating system.

  • CVE-2024-42502HigSep 17, 2024
    risk 0.47cvss 7.2epss 0.02

    Authenticated command injection vulnerability exists in the ArubaOS command line interface. Successful exploitation of this vulnerability result in the ability to inject shell commands on the underlying operating system.

  • CVE-2024-8281HigSep 13, 2024
    risk 0.47cvss 7.2epss 0.01

    An input validation weakness was discovered in XCC that could allow a valid, authenticated XCC user with elevated privileges to perform command injection through specially crafted command line input in the XCC SSH captive shell.

  • CVE-2024-8280HigSep 13, 2024
    risk 0.47cvss 7.2epss 0.01

    An input validation weakness was discovered in XCC that could allow a valid, authenticated XCC user with elevated privileges to perform command injection or cause a recoverable denial of service using a specially crafted file.

  • CVE-2024-8279HigSep 13, 2024
    risk 0.47cvss 7.2epss 0.01

    A privilege escalation vulnerability was discovered in XCC that could allow a valid, authenticated XCC user with elevated privileges to perform command injection via specially crafted file uploads.

  • CVE-2024-8278HigSep 13, 2024
    risk 0.47cvss 7.2epss 0.01

    A privilege escalation vulnerability was discovered in XCC that could allow a valid, authenticated XCC user with elevated privileges to perform command injection via specially crafted IPMI commands.

  • CVE-2024-8686HigSep 11, 2024
    risk 0.47cvss 7.2epss 0.01

    A command injection vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as root on the firewall.

  • CVE-2024-20483HigSep 11, 2024
    risk 0.47cvss 7.2epss 0.01

    Multiple vulnerabilities in Cisco Routed PON Controller Software, which runs as a docker container on hardware that is supported by Cisco IOS XR Software, could allow an authenticated, remote attacker with Administrator-level privileges on the PON Manager or direct access to the…

  • CVE-2023-39300HigSep 6, 2024
    risk 0.47cvss 7.2epss 0.01

    An OS command injection vulnerability has been reported to affect legacy QTS. If exploited, the vulnerability could allow authenticated administrators to execute commands via a network. We have already fixed the vulnerability in the following versions: QTS 4.3.6.2805 build…

  • CVE-2024-7203HigSep 3, 2024
    risk 0.47cvss 7.2epss 0.01

    A post-authentication command injection vulnerability in Zyxel ATP series firmware versions from V4.60 through V5.38 and USG FLEX series firmware versions from V4.60 through V5.38 could allow an authenticated attacker with administrator privileges to execute some operating…