VYPR

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-15 · CAPEC-43 · CAPEC-6 · CAPEC-88

CVEs mapped to this weakness (6,524)

page 225 of 327
  • CVE-2024-31162HigJun 14, 2024
    risk 0.47cvss 7.2epss 0.01

    The specific function parameter of ASUS Download Master does not properly filter user input. An unauthenticated remote attacker with administrative privileges can exploit this vulnerability to execute arbitrary system commands on the device.

  • CVE-2024-5403HigMay 27, 2024
    risk 0.47cvss 7.2epss 0.01

    ASKEY 5G NR Small Cell fails to properly filter user input for certain functionality, allowing remote attackers with administrator privilege to execute arbitrary system commands on the remote server.

  • CVE-2024-5399HigMay 27, 2024
    risk 0.47cvss 7.2epss 0.01

    Openfind Mail2000 does not properly filter parameters of specific API. Remote attackers with administrative privileges can exploit this vulnerability to execute arbitrary system commands on the remote server.

  • CVE-2024-33529HigMay 21, 2024
    risk 0.47cvss 7.2epss 0.01

    ILIAS 7 before 7.30 and ILIAS 8 before 8.11 as well as ILIAS 9.0 allow remote authenticated attackers with administrative privileges to execute operating system commands via file uploads with dangerous types.

  • CVE-2024-0401HigMay 20, 2024
    risk 0.47cvss 7.2epss 0.01

    ASUS routers supporting custom OpenVPN profiles are vulnerable to a code execution vulnerability. An authenticated and remote attacker can execute arbitrary operating system commands by uploading a crafted OVPN profile. Known affected routers include ASUS ExpertWiFi, ASUS…

  • CVE-2023-6321HigMay 15, 2024
    risk 0.47cvss 7.2epss 0.03

    A command injection vulnerability exists in the IOCTL that manages OTA updates. A specially crafted command can lead to command execution as the root user. An attacker can make authenticated requests to trigger this vulnerability.

  • CVE-2024-31477HigMay 14, 2024
    risk 0.47cvss 7.2epss 0.01

    Multiple authenticated command injection vulnerabilities exist in the command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system.

  • CVE-2024-31476HigMay 14, 2024
    risk 0.47cvss 7.2epss 0.01

    Multiple authenticated command injection vulnerabilities exist in the command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system.

  • CVE-2024-4299HigApr 29, 2024
    risk 0.47cvss 7.2epss 0.02

    The system configuration interface of HGiga iSherlock (including MailSherlock, SpamSherock, AuditSherlock) fails to filter special characters in certain function parameters, allowing remote attackers with administrative privileges to exploit this vulnerability for Command…

  • CVE-2024-4298HigApr 29, 2024
    risk 0.47cvss 7.2epss 0.02

    The email search interface of HGiga iSherlock (including MailSherlock, SpamSherock, AuditSherlock) fails to filter special characters in certain function parameters, allowing remote attackers with administrative privileges to exploit this vulnerability for Command Injection…

  • CVE-2024-2659HigApr 15, 2024
    risk 0.47cvss 7.2epss 0.01

    A command injection vulnerability was identified in SMM/SMM2 and FPC that could allow an authenticated user with elevated privileges to execute system commands when performing a specific administrative function.

  • CVE-2023-4855HigApr 15, 2024
    risk 0.47cvss 7.2epss 0.01

    A command injection vulnerability was identified in SMM/SMM2 and FPC that could allow an authenticated user with elevated privileges to execute unauthorized commands via IPMI.

  • CVE-2024-22423HigApr 9, 2024
    risk 0.47cvss 8.3epss 0.01

    yt-dlp is a youtube-dl fork with additional features and fixes. The patch that addressed CVE-2023-40581 attempted to prevent RCE when using `--exec` with `%q` by replacing double quotes with two double quotes. However, this escaping is not sufficient, and still allows expansion…

  • CVE-2024-29167HigApr 4, 2024
    risk 0.47cvss 7.2epss 0.01

    SVR-116 firmware version 1.6.0.30028871 allows a remote authenticated attacker with an administrative privilege to execute arbitrary OS commands by sending a specially crafted request to the product.

  • CVE-2024-25955HigMar 28, 2024
    risk 0.47cvss 7.2epss 0.01

    Dell vApp Manager, versions prior to 9.2.4.9 contain a Command Injection Vulnerability. An authorized attacker could potentially exploit this vulnerability leading to an execution of an inserted command. Dell recommends customers to upgrade at the earliest opportunity.

  • CVE-2024-25946HigMar 28, 2024
    risk 0.47cvss 7.2epss 0.01

    Dell vApp Manager, versions prior to 9.2.4.9 contain a Command Injection Vulnerability. An authorized attacker could potentially exploit this vulnerability leading to an execution of an inserted command. Dell recommends customers to upgrade at the earliest opportunity.

  • CVE-2024-24899HigMar 25, 2024
    risk 0.47cvss 7.2epss 0.02

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in openEuler aops-zeus on Linux allows Command Injection. This vulnerability is associated with program files https://gitee.Com/openeuler/aops-zeus/blob/master/zeus/conf/const…

  • CVE-2024-1683HigFeb 23, 2024
    risk 0.47cvss 7.3epss 0.00

    A DLL injection vulnerability exists where an authenticated, low-privileged local attacker could modify application files on the TIE Secure Relay host, which could allow for overriding of the configuration and running of new Secure Relay services.

  • CVE-2023-6398HigFeb 20, 2024
    risk 0.47cvss 7.2epss 0.01

    A post-authentication command injection vulnerability in the file upload binary in Zyxel ATP series firmware versions from 4.32 through 5.37 Patch 1, USG FLEX series firmware versions from 4.50 through 5.37 Patch 1, USG FLEX 50(W) series firmware versions from 4.16 through 5.37…

  • CVE-2024-22426HigFeb 16, 2024
    risk 0.47cvss 7.2epss 0.01

    Dell RecoverPoint for Virtual Machines 5.3.x, 6.0.SP1 contains an OS Command injection vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to execute arbitrary operating system commands, which will get executed in the context…