VYPR

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-15 · CAPEC-43 · CAPEC-6 · CAPEC-88

CVEs mapped to this weakness (6,524)

page 228 of 327
  • CVE-2023-39416HigAug 18, 2023
    risk 0.47cvss 7.2epss 0.01

    Proself Enterprise/Standard Edition Ver5.61 and earlier, Proself Gateway Edition Ver1.62 and earlier, and Proself Mail Sanitize Edition Ver1.07 and earlier allow a remote authenticated attacker with an administrative privilege to execute arbitrary OS commands.

  • CVE-2023-34215HigAug 17, 2023
    risk 0.47cvss 7.2epss 0.01

    TN-5900 Series firmware versions v3.3 and prior are vulnerable to the command-injection vulnerability. This vulnerability stems from insufficient input validation and improper authentication in the certification-generation function, which could potentially allow malicious users…

  • CVE-2023-34214HigAug 17, 2023
    risk 0.47cvss 7.2epss 0.00

    TN-4900 Series firmware versions v1.2.4 and prior and TN-5900 Series firmware versions v3.3 and prior are vulnerable to the command-injection vulnerability. This vulnerability stems from insufficient input validation in the certificate-generation function, which could…

  • CVE-2023-33238HigAug 17, 2023
    risk 0.47cvss 7.2epss 0.01

    TN-4900 Series firmware versions v1.2.4 and prior and TN-5900 Series firmware versions v3.3 and prior are vulnerable to the command injection vulnerability. This vulnerability stems from inadequate input validation in the certificate management function, which could potentially…

  • CVE-2023-3260HigAug 14, 2023
    risk 0.47cvss 7.2epss 0.01

    The Dataprobe iBoot PDU running firmware version 1.43.03312023 or earlier is vulnerable to command injection via the `user-name` URL parameter. An authenticated malicious agent can exploit this vulnerability to execute arbitrary command on the underlying Linux operating system.

  • CVE-2023-37863HigAug 9, 2023
    risk 0.47cvss 7.2epss 0.01

    In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with SNMPv2 write privileges may use an a special SNMP request to gain full access to the device.

  • CVE-2023-21411HigAug 3, 2023
    risk 0.47cvss 7.2epss 0.01

    User provided input is not sanitized in the “Settings > Access Control” configuration interface allowing for arbitrary code execution.

  • CVE-2023-21410HigAug 3, 2023
    risk 0.47cvss 7.2epss 0.01

    User provided input is not sanitized on the AXIS License Plate Verifier specific “api.cgi” allowing for arbitrary code execution.

  • CVE-2023-35019HigJul 31, 2023
    risk 0.47cvss 7.2epss 0.01

    IBM Security Verify Governance, Identity Manager 10.0 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 257873.

  • CVE-2023-38056HigJul 24, 2023
    risk 0.47cvss 7.2epss 0.01

    Improper Neutralization of commands allowed to be executed via OTRS System Configuration e.g. SchedulerCronTaskModule using UnitTests modules allows any authenticated attacker with admin privileges local execution of Code.This issue affects OTRS: from 7.0.X before 7.0.45, from…

  • CVE-2023-23777HigJul 11, 2023
    risk 0.47cvss 7.2epss 0.01

    An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in FortiWeb version 7.0.1 and below, 6.4 all versions, version 6.3.18 and below may allow a privileged attacker to execute arbitrary bash commands via crafted cli…

  • CVE-2023-25583HigJul 6, 2023
    risk 0.47cvss 7.2epss 0.04

    Two OS command injection vulnerabilities exist in the zebra vlan_name functionality of Milesight UR32L v32.3.0.5. A specially crafted network request can lead to command execution. An attacker can send a network request to trigger these vulnerabilities.This command injection is…

  • CVE-2023-25582HigJul 6, 2023
    risk 0.47cvss 7.2epss 0.04

    Two OS command injection vulnerabilities exist in the zebra vlan_name functionality of Milesight UR32L v32.3.0.5. A specially crafted network request can lead to command execution. An attacker can send a network request to trigger these vulnerabilities.This command injection is…

  • CVE-2023-24595HigJul 6, 2023
    risk 0.47cvss 7.2epss 0.04

    An OS command injection vulnerability exists in the ys_thirdparty system_user_script functionality of Milesight UR32L v32.3.0.5. A specially crafted series of network requests can lead to command execution. An attacker can send a sequence of requests to trigger this…

  • CVE-2023-23550HigJul 6, 2023
    risk 0.47cvss 7.2epss 0.04

    An OS command injection vulnerability exists in the ys_thirdparty user_delete functionality of Milesight UR32L v32.3.0.5. A specially crafted network packet can lead to command execution. An attacker can send a sequence of requests to trigger this vulnerability.

  • CVE-2023-22659HigJul 6, 2023
    risk 0.47cvss 7.2epss 0.04

    An os command injection vulnerability exists in the libzebra.so change_hostname functionality of Milesight UR32L v32.3.0.5. A specially-crafted network packets can lead to command execution. An attacker can send a sequence of requests to trigger this vulnerability.

  • CVE-2023-22365HigJul 6, 2023
    risk 0.47cvss 7.2epss 0.02

    An OS command injection vulnerability exists in the ys_thirdparty check_system_user functionality of Milesight UR32L v32.3.0.5. A specially crafted set of network packets can lead to command execution. An attacker can send a network request to trigger this vulnerability.

  • CVE-2023-36622HigJul 5, 2023
    risk 0.47cvss 7.2epss 0.01

    The websocket configuration endpoint of the Loxone Miniserver Go Gen.2 before 14.1.5.9 allows remote authenticated administrators to inject arbitrary OS commands via the timezone parameter.

  • CVE-2023-32622HigJun 30, 2023
    risk 0.47cvss 7.2epss 0.01

    Improper neutralization of special elements in WL-WN531AX2 firmware versions prior to 2023526 allows an attacker with an administrative privilege to execute OS commands with the root privilege.

  • CVE-2023-3333HigJun 28, 2023
    risk 0.47cvss 7.2epss 0.01

    Improper Neutralization of Special Elements used in an OS Command vulnerability in NEC Corporation Aterm WG2600HP2, WG2600HP, WG2200HP, WG1800HP2, WG1800HP, WG1400HP, WG600HP, WG300HP, WF300HP, WR9500N, WR9300N, WR8750N, WR8700N, WR8600N, WR8370N, WR8175N and WR8170N all…