VYPR

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-15 · CAPEC-43 · CAPEC-6 · CAPEC-88

CVEs mapped to this weakness (6,475)

page 277 of 324
  • CVE-2021-4242MedNov 30, 2022
    risk 0.41cvss 6.3epss 0.03

    A vulnerability was found in Sapido BR270n, BRC76n, GR297 and RB1732 and classified as critical. Affected by this issue is some unknown functionality of the file ip/syscmd.htm. The manipulation leads to os command injection. The attack may be launched remotely. The exploit has…

  • CVE-2022-20926MedNov 15, 2022
    risk 0.41cvss 6.3epss 0.01

    A vulnerability in the web management interface of the Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system. The vulnerability is due to insufficient validation of…

  • CVE-2022-20925MedNov 15, 2022
    risk 0.41cvss 6.3epss 0.01

    A vulnerability in the web management interface of the Cisco Firepower Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system. The vulnerability is due to insufficient validation of…

  • CVE-2022-3492MedOct 13, 2022
    risk 0.41cvss 6.3epss 0.01

    A vulnerability classified as critical was found in SourceCodester Human Resource Management System 1.0. This vulnerability affects unknown code of the component Profile Photo Handler. The manipulation of the argument parameter leads to os command injection. The attack can be…

  • CVE-2022-34769MedAug 5, 2022
    risk 0.41cvss 6.3epss 0.00

    Michlol - rashim web interface Insecure direct object references (IDOR). First of all, the attacker needs to login. After he performs log into the system there are some functionalities that the specific user is not allowed to perform. However all the attacker needs to do in…

  • CVE-2021-23154MedJan 10, 2022
    risk 0.41cvss 6.3epss 0.01

    In Lens prior to 5.3.4, custom helm chart configuration creates helm commands from string concatenation of provided arguments which are then executed in the user's shell. Arguments can be provided which cause arbitrary shell commands to run on the system.

  • CVE-2021-22125MedJul 20, 2021
    risk 0.41cvss 6.3epss 0.01

    An instance of improper neutralization of special elements in the sniffer module of FortiSandbox before 3.2.2 may allow an authenticated administrator to execute commands on the underlying system's shell via altering the content of its configuration file.

  • CVE-2021-34616MedJul 8, 2021
    risk 0.41cvss 6.3epss 0.01

    A remote arbitrary command execution vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.10.0, 6.9.6 and 6.8.9. Aruba has released updates to ClearPass Policy Manager that address this security vulnerability.

  • CVE-2021-34615MedJul 8, 2021
    risk 0.41cvss 6.3epss 0.01

    A remote arbitrary command execution vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.10.0, 6.9.6 and 6.8.9. Aruba has released updates to ClearPass Policy Manager that address this security vulnerability.

  • CVE-2021-34613MedJul 8, 2021
    risk 0.41cvss 6.3epss 0.01

    A remote arbitrary command execution vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.10.0, 6.9.6 and 6.8.9. Aruba has released updates to ClearPass Policy Manager that address this security vulnerability.

  • CVE-2021-34612MedJul 8, 2021
    risk 0.41cvss 6.3epss 0.01

    A remote arbitrary command execution vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.10.0, 6.9.6 and 6.8.9. Aruba has released updates to ClearPass Policy Manager that address this security vulnerability.

  • CVE-2021-34614MedJul 8, 2021
    risk 0.41cvss 6.3epss 0.01

    A remote arbitrary command execution vulnerability was discovered in Aruba ClearPass Policy Manager version(s): Prior to 6.10.0, 6.9.6 and 6.8.9. Aruba has released updates to ClearPass Policy Manager that address this security vulnerability.

  • CVE-2021-26970MedMar 5, 2021
    risk 0.41cvss 6.3epss 0.01

    A remote authenticated arbitrary command execution vulnerability was discovered in Aruba AirWave Management Platform version(s): Prior to 8.2.12.0. Vulnerabilities in the AirWave web-base management interface could allow remote authenticated users to run arbitrary commands on…

  • CVE-2021-21289HigFeb 2, 2021
    risk 0.41cvss 7.4epss 0.04

    Mechanize is an open-source ruby library that makes automated web interaction easy. In Mechanize from version 2.0.0 and before version 2.7.7 there is a command injection vulnerability. Affected versions of mechanize allow for OS commands to be injected using several classes'…

  • CVE-2020-26294HigJan 4, 2021
    risk 0.41cvss 7.4epss 0.02

    Vela is a Pipeline Automation (CI/CD) framework built on Linux container technology written in Golang. In Vela compiler before version 0.6.1 there is a vulnerability which allows exposure of server configuration. It impacts all users of Vela. An attacker can use Sprig's `env`…

  • CVE-2020-7778HigNov 26, 2020
    risk 0.41cvss 7.3epss 0.02

    This affects the package systeminformation before 4.30.2. The attacker can overwrite the properties and functions of an object, which can lead to executing OS commands.

  • CVE-2020-3371MedNov 6, 2020
    risk 0.41cvss 6.3epss 0.02

    A vulnerability in the web UI of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to inject arbitrary code and execute arbitrary commands at the underlying operating system level. The vulnerability is due to insufficient input…

  • CVE-2020-3602MedOct 8, 2020
    risk 0.41cvss 6.3epss 0.00

    A vulnerability in the CLI of Cisco StarOS operating system for Cisco ASR 5000 Series Routers could allow an authenticated, local attacker to elevate privileges on an affected device. The vulnerability is due to insufficient input validation of CLI commands. An attacker could…

  • CVE-2020-3377MedJul 31, 2020
    risk 0.41cvss 6.3epss 0.01

    A vulnerability in the Device Manager application of Cisco Data Center Network Manager (DCNM) could allow an authenticated, remote attacker to inject arbitrary commands on the affected device. The vulnerability is due to insufficient validation of user-supplied input. An…

  • CVE-2020-1734HigMar 3, 2020
    risk 0.41cvss 7.4epss 0.00

    A flaw was found in the pipe lookup plugin of ansible. Arbitrary commands can be run, when the pipe lookup plugin uses subprocess.Popen() with shell=True, by overwriting ansible facts and the variable is not escaped by quote plugin. An attacker could take advantage and run…