VYPR

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

BaseStableLikelihood: High

Description

The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-108 · CAPEC-15 · CAPEC-43 · CAPEC-6 · CAPEC-88

CVEs mapped to this weakness (6,524)

page 96 of 327
  • CVE-2022-45768HigFeb 7, 2023
    risk 0.59cvss 8.8epss 0.29

    Command Injection vulnerability in Edimax Technology Co., Ltd. Wireless Router N300 Firmware BR428nS v3 allows attacker to execute arbitrary code via the formWlanMP function.

  • CVE-2022-47911CriJan 18, 2023
    risk 0.59cvss 9.1epss 0.01

    Sewio’s Real-Time Location System (RTLS) Studio version 2.0.0 up to and including version 2.6.2 does not properly validate the input module name to the backup services of the software. This could allow a remote attacker to access sensitive functions of the application and…

  • CVE-2022-43483CriJan 18, 2023
    risk 0.59cvss 9.1epss 0.01

    Sewio’s Real-Time Location System (RTLS) Studio version 2.0.0 up to and including version 2.6.2 does not properly validate the input module name to the monitor services of the software. This could allow a remote attacker to access sensitive functions of the application and…

  • CVE-2022-45942HigDec 20, 2022
    risk 0.59cvss 8.8epss 0.22

    A Remote Code Execution (RCE) vulnerability was found in includes/baijiacms/common.inc.php in baijiacms v4.

  • CVE-2022-42139HigDec 14, 2022
    risk 0.59cvss 8.8epss 0.18

    Delta Electronics DVW-W02W2-E2 1.5.0.10 is vulnerable to Command Injection via Crafted URL.

  • CVE-2021-44171CriOct 10, 2022
    risk 0.59cvss 9.0epss 0.02

    A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiOS version 6.0.0 through 6.0.14, FortiOS version 6.2.0 through 6.2.10, FortiOS version 6.4.0 through 6.4.8, FortiOS version 7.0.0 through 7.0.3 allows attacker to…

  • CVE-2022-30079HigSep 8, 2022
    risk 0.59cvss 8.8epss 0.25

    Command injection vulnerability was discovered in Netgear R6200 v2 firmware through R6200v2-V1.0.3.12 via binary /sbin/acos_service that could allow remote authenticated attackers the ability to modify values in the vulnerable parameter.

  • CVE-2022-32572HigAug 22, 2022
    risk 0.59cvss 8.8epss 0.24

    An os command injection vulnerability exists in the aVideoEncoder wget functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can send an HTTP request to trigger this vulnerability.

  • CVE-2022-35975CriAug 18, 2022
    risk 0.59cvss 9.0epss 0.01

    The GitOps Tools Extension for VSCode can make it easier to manage Flux objects. A specially crafted Flux object may allow for remote code execution in the machine running the extension, in the context of the user that is running VSCode. Users using the VSCode extension to…

  • CVE-2022-36309HigAug 16, 2022
    risk 0.59cvss 8.8epss 0.24

    Airspan AirVelocity 1500 software versions prior to 15.18.00.2511 have a root command injection vulnerability in the ActiveBank parameter of the recoverySubmit.cgi script running on the eNodeB's web management UI. This issue may affect other AirVelocity and AirSpeed models.

  • CVE-2022-20827CriAug 10, 2022
    risk 0.59cvss 9.0epss 0.02

    Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an unauthenticated, remote attacker to execute arbitrary code or cause a denial of service (DoS) condition on an affected device. For more information about these…

  • CVE-2022-25048HigJul 7, 2022
    risk 0.59cvss 8.8epss 0.19

    Command injection vulnerability in CWP v0.9.8.1126 that allows normal users to run commands as the root user.

  • CVE-2022-2253CriJul 1, 2022
    risk 0.59cvss 9.1epss 0.01

    A user with administrative privileges in Distributed Data Systems WebHMI 4.1.1.7662 may send OS commands to execute on the host server.

  • CVE-2022-30425HigJun 2, 2022
    risk 0.59cvss 8.8epss 0.20

    Tenda Technology Co.,Ltd HG6 3.3.0-210926 was discovered to contain a command injection vulnerability via the pingAddr and traceAddr parameters. This vulnerability is exploited via a crafted POST request.

  • CVE-2022-23666CriMay 16, 2022
    risk 0.59cvss 9.1epss 0.02

    A authenticated remote command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to ClearPass Policy Manager that address this security…

  • CVE-2022-23665CriMay 16, 2022
    risk 0.59cvss 9.1epss 0.02

    A authenticated remote command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to ClearPass Policy Manager that address this security…

  • CVE-2022-23664CriMay 16, 2022
    risk 0.59cvss 9.1epss 0.02

    A authenticated remote command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to ClearPass Policy Manager that address this security…

  • CVE-2022-23663CriMay 16, 2022
    risk 0.59cvss 9.1epss 0.02

    A authenticated remote command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to ClearPass Policy Manager that address this security…

  • CVE-2022-23662CriMay 16, 2022
    risk 0.59cvss 9.1epss 0.02

    A authenticated remote command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to ClearPass Policy Manager that address this security…

  • CVE-2022-23661CriMay 16, 2022
    risk 0.59cvss 9.1epss 0.02

    A authenticated remote command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to ClearPass Policy Manager that address this security…