Vulnerabilities > Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

DATE CVE VULNERABILITY TITLE RISK
2020-03-20 CVE-2019-19148 OS Command Injection vulnerability in Tellabs Optical Line Terminal 1150 Firmware Ont709.2.50.12
Tellabs Optical Line Terminal (OLT) 1150 devices allow Remote Command Execution via the -l option to TELNET or SSH.
network
low complexity
tellabs CWE-78
critical
9.8
2020-03-20 CVE-2019-19487 OS Command Injection vulnerability in Centreon
Command Injection in minPlayCommand.php in Centreon (19.04.4 and below) allows an attacker to achieve command injection via a plugin test.
network
low complexity
centreon CWE-78
8.8
2020-03-20 CVE-2018-20334 OS Command Injection vulnerability in Asus Asuswrt 3.0.0.4.384.20308
An issue was discovered in ASUSWRT 3.0.0.4.384.20308.
network
low complexity
asus CWE-78
critical
9.8
2020-03-20 CVE-2019-16072 OS Command Injection vulnerability in Netsas Enigma Network Management Solution
An OS command injection vulnerability in the discover_and_manage CGI script in NETSAS Enigma NMS 65.0.0 and prior allows an attacker to execute arbitrary code because of improper neutralization of shell metacharacters in the ip_address variable within an snmp_browser action.
network
low complexity
netsas CWE-78
critical
9.8
2020-03-19 CVE-2020-3266 OS Command Injection vulnerability in Cisco Sd-Wan Firmware
A vulnerability in the CLI of Cisco SD-WAN Solution software could allow an authenticated, local attacker to inject arbitrary commands that are executed with root privileges.
local
low complexity
cisco CWE-78
7.8
2020-03-18 CVE-2020-10674 OS Command Injection vulnerability in Perlspeak Project Perlspeak
PerlSpeak through 2.01 allows attackers to execute arbitrary OS commands, as demonstrated by use of system and 2-argument open.
network
low complexity
perlspeak-project CWE-78
critical
9.8
2020-03-18 CVE-2019-12132 OS Command Injection vulnerability in Onap Open Network Automation Platform
An issue was discovered in ONAP SDNC before Dublin.
network
low complexity
onap CWE-78
critical
9.8
2020-03-18 CVE-2019-12123 OS Command Injection vulnerability in Onap Open Network Automation Platform
An issue was discovered in ONAP SDNC before Dublin.
network
low complexity
onap CWE-78
8.8
2020-03-18 CVE-2019-12113 OS Command Injection vulnerability in Onap Open Network Automation Platform 3.0.0/3.0.1/3.0.2
An issue was discovered in ONAP SDNC before Dublin.
network
low complexity
onap CWE-78
8.8
2020-03-18 CVE-2019-12112 OS Command Injection vulnerability in Onap Open Network Automation Platform
An issue was discovered in ONAP SDNC before Dublin.
network
low complexity
onap CWE-78
critical
9.8