VYPR

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-15 · CAPEC-43 · CAPEC-6 · CAPEC-88

CVEs mapped to this weakness (6,524)

page 230 of 327
  • CVE-2023-22280HigJan 17, 2023
    risk 0.47cvss 7.2epss 0.01

    MAHO-PBX NetDevancer Lite/Uni/Pro/Cloud prior to Ver.1.11.00, MAHO-PBX NetDevancer VSG Lite/Uni prior to Ver.1.11.00, and MAHO-PBX NetDevancer MobileGate Home/Office prior to Ver.1.11.00 allow a remote authenticated attacker with an administrative privilege to execute an…

  • CVE-2022-42290HigJan 13, 2023
    risk 0.47cvss 7.2epss 0.01

    NVIDIA BMC contains a vulnerability in SPX REST API, where an authorized attacker can inject arbitrary shell commands, which may lead to code execution, denial of service, information disclosure and data tampering.

  • CVE-2022-42289HigJan 13, 2023
    risk 0.47cvss 7.2epss 0.01

    NVIDIA BMC contains a vulnerability in SPX REST API, where an authorized attacker can inject arbitrary shell commands, which may lead to code execution, denial of service, information disclosure and data tampering.

  • CVE-2022-42279HigJan 13, 2023
    risk 0.47cvss 7.2epss 0.01

    NVIDIA BMC contains a vulnerability in SPX REST API, where an authorized attacker can inject arbitrary shell commands, which may lead to code execution, denial of service, information disclosure and data tampering.

  • CVE-2023-22598HigJan 12, 2023
    risk 0.47cvss 7.2epss 0.02

    InHand Networks InRouter 302, prior to version IR302 V3.5.56, and InRouter 615, prior to version InRouter6XX-S-V2.3.0.r5542, contain vulnerability CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'). An unauthorized user with…

  • CVE-2022-43973HigJan 9, 2023
    risk 0.47cvss 7.2epss 0.02

    An arbitrary code execution vulnerability exisits in Linksys WRT54GL Wireless-G Broadband Router with firmware <= 4.30.18.006. The Check_TSSI function within the httpd binary uses unvalidated user input in the construction of a system command. An authenticated attacker with…

  • CVE-2022-43971HigJan 9, 2023
    risk 0.47cvss 7.2epss 0.02

    An arbitrary code exection vulnerability exists in Linksys WUMC710 Wireless-AC Universal Media Connector with firmware <= 1.0.02 (build3). The do_setNTP function within the httpd binary uses unvalidated user input in the construction of a system command. An authenticated…

  • CVE-2022-43538HigJan 5, 2023
    risk 0.47cvss 7.2epss 0.01

    Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the underlying host. Successful exploits could allow an attacker to execute arbitrary commands as root on the underlying operating system…

  • CVE-2022-43537HigJan 5, 2023
    risk 0.47cvss 7.2epss 0.01

    Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the underlying host. Successful exploits could allow an attacker to execute arbitrary commands as root on the underlying operating system…

  • CVE-2022-43536HigJan 5, 2023
    risk 0.47cvss 7.2epss 0.01

    Vulnerabilities in the ClearPass Policy Manager web-based management interface allow remote authenticated users to run arbitrary commands on the underlying host. Successful exploits could allow an attacker to execute arbitrary commands as root on the underlying operating system…

  • CVE-2022-40740HigJan 3, 2023
    risk 0.47cvss 7.2epss 0.01

    Realtek GPON router has insufficient filtering for special characters. A remote attacker authenticated as an administrator can exploit this vulnerability to perform command injection attacks, to execute arbitrary system command, manipulate system or disrupt service.

  • CVE-2022-42140HigDec 14, 2022
    risk 0.47cvss 7.2epss 0.02

    Delta Electronics DX-2100-L1-CN 2.42 is vulnerable to Command Injection via lform/net_diagnose.

  • CVE-2022-45996HigDec 12, 2022
    risk 0.47cvss 7.2epss 0.02

    Tenda W20E V16.01.0.6(3392) is vulnerable to Command injection via cmd_get_ping_output.

  • CVE-2022-37924HigDec 12, 2022
    risk 0.47cvss 7.2epss 0.02

    Vulnerabilities in the Aruba EdgeConnect Enterprise command line interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system…

  • CVE-2022-37912HigDec 12, 2022
    risk 0.47cvss 7.2epss 0.02

    Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities results in the ability to execute arbitrary commands as a privileged user on the underlying operating system.

  • CVE-2022-37902HigDec 12, 2022
    risk 0.47cvss 7.2epss 0.02

    Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities results in the ability to execute arbitrary commands as a privileged user on the underlying operating system.

  • CVE-2022-37901HigDec 12, 2022
    risk 0.47cvss 7.2epss 0.02

    Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities results in the ability to execute arbitrary commands as a privileged user on the underlying operating system.

  • CVE-2022-37900HigDec 12, 2022
    risk 0.47cvss 7.2epss 0.02

    Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities results in the ability to execute arbitrary commands as a privileged user on the underlying operating system.

  • CVE-2022-37899HigDec 12, 2022
    risk 0.47cvss 7.2epss 0.02

    Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities results in the ability to execute arbitrary commands as a privileged user on the underlying operating system.

  • CVE-2022-37898HigDec 12, 2022
    risk 0.47cvss 7.2epss 0.01

    Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities results in the ability to execute arbitrary commands as a privileged user on the underlying operating system.