VYPR

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-15 · CAPEC-43 · CAPEC-6 · CAPEC-88

CVEs mapped to this weakness (6,524)

page 94 of 327
  • CVE-2025-46271CriApr 24, 2025
    risk 0.59cvss 9.1epss 0.02

    UNI-NMS-Lite is vulnerable to a command injection attack that could allow an unauthenticated attacker to read or manipulate device data.

  • CVE-2024-41790CriApr 8, 2025
    risk 0.59cvss 9.1epss 0.01

    A vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected devices does not sanitize the region parameter in specific POST requests. This could allow an authenticated remote attacker to execute arbitrary code with root…

  • CVE-2024-41789CriApr 8, 2025
    risk 0.59cvss 9.1epss 0.01

    A vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected devices does not sanitize the language parameter in specific POST requests. This could allow an authenticated remote attacker to execute arbitrary code with root…

  • CVE-2024-41788CriApr 8, 2025
    risk 0.59cvss 9.1epss 0.01

    A vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected devices does not sanitize the input parameters in specific GET requests. This could allow an authenticated remote attacker to execute arbitrary code with root…

  • CVE-2025-24383CriMar 28, 2025
    risk 0.59cvss 9.1epss 0.01

    Dell Unity, version(s) 5.4 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability to delete arbitrary files.…

  • CVE-2024-51450CriFeb 6, 2025
    risk 0.59cvss 9.1epss 0.01

    IBM Security Verify Directory 10.0.0 through 10.0.3 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request.

  • CVE-2024-11006CriNov 12, 2024
    risk 0.59cvss 9.1epss 0.02

    Command injection in Ivanti Connect Secure before version 22.7R2.1 (Not Applicable to 9.1Rx) and Ivanti Policy Secure before version 22.7R1.1 (Not Applicable to 9.1Rx) allows a remote authenticated attacker with admin privileges to achieve remote code execution.

  • CVE-2024-11005CriNov 12, 2024
    risk 0.59cvss 9.1epss 0.02

    Command injection in Ivanti Connect Secure before version 22.7R2.1 (Not Applicable to 9.1Rx) and Ivanti Policy Secure before version 22.7R1.1 (Not Applicable to 9.1Rx) allows a remote authenticated attacker with admin privileges to achieve remote code execution.

  • CVE-2024-11007CriNov 12, 2024
    risk 0.59cvss 9.1epss 0.02

    Command injection in Ivanti Connect Secure before version 22.7R2.1 (Not Applicable to 9.1Rx) and Ivanti Policy Secure before version 22.7R1.1 (Not Applicable to 9.1Rx) allows a remote authenticated attacker with admin privileges to achieve remote code execution.

  • CVE-2024-46890CriNov 12, 2024
    risk 0.59cvss 9.1epss 0.01

    A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 3). The affected application does not properly validate input sent to specific endpoints of its web API. This could allow an authenticated remote attacker with high privileges on the application to…

  • CVE-2024-45763CriNov 8, 2024
    risk 0.59cvss 9.1epss 0.01

    Dell Enterprise SONiC OS, version(s) 4.1.x, 4.2.x, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to…

  • CVE-2024-45765CriNov 8, 2024
    risk 0.59cvss 9.1epss 0.01

    Dell Enterprise SONiC OS, version(s) 4.1.x, 4.2.x, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to…

  • CVE-2024-10915HigNov 6, 2024
    risk 0.59cvss 8.1epss 0.79

    A vulnerability was found in D-Link DNS-320, DNS-320LW, DNS-325 and DNS-340L up to 20241028. It has been rated as critical. Affected by this issue is the function cgi_user_add of the file /cgi-bin/account_mgr.cgi?cmd=cgi_user_add. The manipulation of the argument group leads to…

  • CVE-2024-51661CriNov 4, 2024
    risk 0.59cvss 9.1epss 0.01

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in David Lingren Media LIbrary Assistant media-library-assistant allows Command Injection.This issue affects Media LIbrary Assistant: from n/a through <= 3.19.

  • CVE-2024-42167CriAug 12, 2024
    risk 0.59cvss 9.1epss 0.00

    The function "generate_app_certificates" in controllers/saml2/saml2.js of FIWARE Keyrock <= 8.4 does not neutralize special elements used in an OS Command properly. This allows an authenticated user with permissions to create applications to execute commands by creating an…

  • CVE-2024-42166CriAug 12, 2024
    risk 0.59cvss 9.1epss 0.00

    The function "generate_app_certificates" in lib/app_certificates.js of FIWARE Keyrock <= 8.4 does not neutralize special elements used in an OS Command properly. This allows an authenticated user with permissions to create applications to execute commands by creating an…

  • CVE-2024-36394CriJun 6, 2024
    risk 0.59cvss 9.1epss 0.01

    SysAid - CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

  • CVE-2024-5411HigMay 28, 2024
    risk 0.59cvss 8.8epss 0.23

    Missing input validation and OS command integration of the input in the ORing IAP-420 web-interface allows authenticated command injection.This issue affects IAP-420 version 2.01e and below.

  • CVE-2023-47709CriMay 14, 2024
    risk 0.59cvss 9.1epss 0.01

    IBM Security Guardium 11.3, 11.4, 11.5, and 12.0 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 271524.

  • CVE-2024-20356HigApr 24, 2024
    risk 0.59cvss 8.7epss 0.33

    A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker with Administrator-level privileges to perform command injection attacks on an affected system and elevate their privileges to…