VYPR

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-15 · CAPEC-43 · CAPEC-6 · CAPEC-88

CVEs mapped to this weakness (6,475)

page 268 of 324
  • CVE-2021-35032MedDec 28, 2021
    risk 0.42cvss 6.4epss 0.00

    A vulnerability in the 'libsal.so' of the Zyxel GS1900 series firmware version 2.60 could allow an authenticated local user to execute arbitrary OS commands via a crafted function call.

  • CVE-2021-3061MedNov 10, 2021
    risk 0.42cvss 6.4epss 0.01

    An OS command injection vulnerability in the Palo Alto Networks PAN-OS command line interface (CLI) enables an authenticated administrator with access to the CLI to execute arbitrary OS commands to escalate privileges. This issue impacts: PAN-OS 8.1 versions earlier than PAN-OS…

  • CVE-2021-41228HigNov 5, 2021
    risk 0.42cvss 7.5epss 0.00

    TensorFlow is an open source platform for machine learning. In affected versions TensorFlow's `saved_model_cli` tool is vulnerable to a code injection as it calls `eval` on user supplied strings. This can be used by attackers to run arbitrary code on the plaform where the CLI…

  • CVE-2021-40120MedNov 4, 2021
    risk 0.42cvss 6.5epss 0.02

    A vulnerability in the web-based management interface of certain Cisco Small Business RV Series Routers could allow an authenticated, remote attacker with administrative privileges to inject arbitrary commands into the underlying operating system and execute them using…

  • CVE-2020-26301HigSep 20, 2021
    risk 0.42cvss 7.5epss 0.04

    ssh2 is client and server modules written in pure JavaScript for node.js. In ssh2 before version 1.4.0 there is a command injection vulnerability. The issue only exists on Windows. This issue may lead to remote code execution if a client of the library calls the vulnerable…

  • CVE-2021-1618MedJul 22, 2021
    risk 0.42cvss 6.5epss 0.03

    Multiple vulnerabilities in the web-based management interface of Cisco Intersight Virtual Appliance could allow an authenticated, remote attacker to conduct a path traversal or command injection attack on an affected system. These vulnerabilities are due to insufficient input…

  • CVE-2020-29499MedJul 19, 2021
    risk 0.42cvss 6.4epss 0.00

    Dell EMC PowerStore versions prior to 1.0.3.0.5.006 contain an OS Command Injection vulnerability in PowerStore X environment . A locally authenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS command on the PowerStore…

  • CVE-2021-1560MedMay 22, 2021
    risk 0.42cvss 6.5epss 0.03

    Multiple vulnerabilities in Cisco DNA Spaces Connector could allow an authenticated, remote attacker to perform a command injection attack on an affected device. These vulnerabilities are due to insufficient input sanitization when executing affected commands. A high-privileged…

  • CVE-2021-1559MedMay 22, 2021
    risk 0.42cvss 6.5epss 0.03

    Multiple vulnerabilities in Cisco DNA Spaces Connector could allow an authenticated, remote attacker to perform a command injection attack on an affected device. These vulnerabilities are due to insufficient input sanitization when executing affected commands. A high-privileged…

  • CVE-2021-23360HigMar 21, 2021
    risk 0.42cvss 7.5epss 0.02

    This affects the package killport before 1.0.2. If (attacker-controlled) user input is given, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function without input sanitization. Running this PoC will cause the command…

  • CVE-2020-27298MedJan 26, 2021
    risk 0.42cvss 6.5epss 0.01

    Philips Interventional Workspot (Release 1.3.2, 1.4.0, 1.4.1, 1.4.3, 1.4.5), Coronary Tools/Dynamic Coronary Roadmap/Stentboost Live (Release 1.0), ViewForum (Release 6.3V1L10). The software constructs all or part of an OS command using externally influenced input from an…

  • CVE-2020-11084MedJul 14, 2020
    risk 0.42cvss 6.4epss 0.01

    In iPear, the manual execution of the eval() function can lead to command injection. Only PCs where commands are manually executed via "For Developers" are affected. This function allows executing any PHP code within iPear which may change, damage, or steal data (files) from the…

  • CVE-2020-7804MedApr 29, 2020
    risk 0.42cvss 6.4epss 0.01

    ActiveX Control(HShell.dll) in Handy Groupware 1.7.3.1 for Windows 7, 8, and 10 allows an attacker to execute arbitrary command via the ShellExec method.

  • CVE-2019-3595MedJul 24, 2019
    risk 0.42cvss 6.5epss 0.01

    Improper Neutralization of Special Elements used in a Command ('Command Injection') in ePO extension in McAfee Data Loss Prevention (DLP) 11.x prior to 11.3.0 allows Authenticated Adminstrator to execute arbitrary code with their local machine privileges via a specially crafted…

  • CVE-2019-1879MedJun 20, 2019
    risk 0.42cvss 6.4epss 0.00

    A vulnerability in the CLI of Cisco Integrated Management Controller (IMC) could allow an authenticated, local attacker to inject arbitrary commands that are executed with root privileges. The vulnerability is due to insufficient validation of user-supplied input at the CLI. An…

  • CVE-2019-1627MedJun 20, 2019
    risk 0.42cvss 6.5epss 0.01

    A vulnerability in the Server Utilities of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to gain unauthorized access to sensitive user information from the configuration data that is stored on the affected system. The vulnerability is…

  • CVE-2019-1732MedMay 15, 2019
    risk 0.42cvss 6.4epss 0.00

    A vulnerability in the Remote Package Manager (RPM) subsystem of Cisco NX-OS Software could allow an authenticated, local attacker with administrator credentials to leverage a time-of-check, time-of-use (TOCTOU) race condition to corrupt local variables, which could lead to…

  • CVE-2019-3727MedMay 15, 2019
    risk 0.42cvss 6.4epss 0.01

    Dell EMC RecoverPoint versions prior to 5.1.3 and RecoverPoint for VMs versions prior to 5.2.0.2 contain an OS command injection vulnerability in the installation feature of Boxmgmt CLI. A malicious boxmgmt user may potentially be able to execute arbitrary commands as root.

  • CVE-2019-10657MedMar 30, 2019
    risk 0.42cvss 6.5epss 0.01

    Grandstream GWN7000 before 1.0.6.32 and GWN7610 before 1.0.8.18 devices allow remote authenticated users to discover passwords via a /ubus/uci.apply config request.

  • CVE-2018-20106MedMar 15, 2019
    risk 0.42cvss 6.5epss 0.01

    In yast2-printer up to and including version 4.0.2 the SMB printer settings don't escape characters in passwords properly. If a password with backticks or simliar characters is supplied this allows for executing code as root. This requires tricking root to enter such a password…