Vulnerabilities > Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

DATE CVE VULNERABILITY TITLE RISK
2021-07-22 CVE-2021-31580 OS Command Injection vulnerability in Akkadianlabs OVA Appliance and Provisioning Manager
The restricted shell provided by Akkadian Provisioning Manager Engine (PME) can be bypassed by switching the OpenSSH channel from `shell` to `exec` and providing the ssh client a single execution parameter.
network
low complexity
akkadianlabs CWE-78
critical
9.8
2021-07-22 CVE-2021-3198 OS Command Injection vulnerability in Ivanti Mobileiron 10.7.0.19/11.0.0.0
By abusing the 'install rpm url' command, an attacker can escape the restricted clish shell on affected versions of Ivanti MobileIron Core.
network
low complexity
ivanti CWE-78
7.2
2021-07-22 CVE-2021-33032 OS Command Injection vulnerability in Eq-3 Homematic Ccu2 Firmware
A Remote Code Execution (RCE) vulnerability in the WebUI component of the eQ-3 HomeMatic CCU2 firmware up to and including version 2.57.5 and CCU3 firmware up to and including version 3.57.5 allows remote unauthenticated attackers to execute system commands as root via a simple HTTP request.
network
low complexity
eq-3 CWE-78
critical
10.0
2021-07-22 CVE-2021-1618 OS Command Injection vulnerability in Cisco Intersight Virtual Appliance 1.0.9148/1.0.9150/1.0.9230
Multiple vulnerabilities in the web-based management interface of Cisco Intersight Virtual Appliance could allow an authenticated, remote attacker to conduct a path traversal or command injection attack on an affected system.
network
low complexity
cisco CWE-78
7.2
2021-07-22 CVE-2021-29143 OS Command Injection vulnerability in Arubanetworks Aos-Cx Firmware
A remote execution of arbitrary commands vulnerability was discovered in Aruba CX 6200F Switch Series, Aruba 6300 Switch Series, Aruba 6400 Switch Series, Aruba 8320 Switch Series, Aruba 8325 Switch Series, Aruba 8400 Switch Series, Aruba CX 8360 Switch Series version(s): Aruba AOS-CX firmware: 10.04.xxxx - versions prior to 10.04.3070, 10.05.xxxx - versions prior to 10.05.0070, 10.06.xxxx - versions prior to 10.06.0110, 10.07.xxxx - versions prior to 10.07.0001.
network
low complexity
arubanetworks CWE-78
7.2
2021-07-21 CVE-2020-21935 OS Command Injection vulnerability in Motorola CX2 Firmware 1.0.2
A command injection vulnerability in HNAP1/GetNetworkTomographySettings of Motorola CX2 router CX 1.0.2 Build 20190508 Rel.97360n allows attackers to execute arbitrary code.
network
low complexity
motorola CWE-78
critical
9.8
2021-07-21 CVE-2020-21937 OS Command Injection vulnerability in Motorola CX2 Firmware 1.0.2
An command injection vulnerability in HNAP1/SetWLanApcliSettings of Motorola CX2 router CX 1.0.2 Build 20190508 Rel.97360n allows attackers to execute arbitrary system commands.
network
low complexity
motorola CWE-78
critical
9.8
2021-07-20 CVE-2021-32751 OS Command Injection vulnerability in Gradle
Gradle is a build tool with a focus on build automation.
network
high complexity
gradle CWE-78
7.5
2021-07-20 CVE-2020-25206 OS Command Injection vulnerability in Mimosa B5 Firmware, B5C Firmware and C5C Firmware
The web console for Mimosa B5, B5c, and C5x firmware through 2.8.0.2 allows authenticated command injection in the Throughput, WANStats, PhyStats, and QosStats API classes.
network
low complexity
mimosa CWE-78
7.2
2021-07-20 CVE-2021-22125 OS Command Injection vulnerability in Fortinet Fortisandbox
An instance of improper neutralization of special elements in the sniffer module of FortiSandbox before 3.2.2 may allow an authenticated administrator to execute commands on the underlying system's shell via altering the content of its configuration file.
network
low complexity
fortinet CWE-78
7.2