Vulnerabilities > Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

DATE CVE VULNERABILITY TITLE RISK
2019-05-15 CVE-2019-1769 OS Command Injection vulnerability in Cisco Nx-Os
A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker with administrator credentials to execute arbitrary commands on the underlying Linux operating system of an attached line card with the privilege level of root.
local
low complexity
cisco CWE-78
6.7
2019-05-15 CVE-2019-1767 OS Command Injection vulnerability in Cisco Nx-Os
A vulnerability in the implementation of a specific CLI command for Cisco NX-OS Software could allow an authenticated, local attacker with administrator credentials to cause a buffer overflow condition or perform command injection.
local
low complexity
cisco CWE-78
7.2
2019-05-15 CVE-2019-11224 OS Command Injection vulnerability in Harman AMX Mvp5150 Firmware 2.87.13
HARMAN AMX MVP5150 v2.87.13 devices allow remote OS Command Injection.
network
low complexity
harman CWE-78
6.5
2019-05-15 CVE-2019-1727 OS Command Injection vulnerability in Cisco Nx-Os
A vulnerability in the Python scripting subsystem of Cisco NX-OS Software could allow an authenticated, local attacker to escape the Python parser and issue arbitrary commands to elevate the attacker's privilege level.
local
low complexity
cisco CWE-78
7.2
2019-05-15 CVE-2013-7285 OS Command Injection vulnerability in Xstream Project Xstream
Xstream API versions up to 1.4.6 and version 1.4.10, if the security framework has not been initialized, may allow a remote attacker to run arbitrary shell commands by manipulating the processed input stream when unmarshaling XML or any supported format.
network
low complexity
xstream-project CWE-78
critical
9.8
2019-05-15 CVE-2019-3727 OS Command Injection vulnerability in Dell products
Dell EMC RecoverPoint versions prior to 5.1.3 and RecoverPoint for VMs versions prior to 5.2.0.2 contain an OS command injection vulnerability in the installation feature of Boxmgmt CLI.
local
low complexity
dell CWE-78
7.2
2019-05-15 CVE-2019-3725 OS Command Injection vulnerability in RSA Netwitness and Security Analytics
RSA Netwitness Platform versions prior to 11.2.1.1 and RSA Security Analytics versions prior to 10.6.6.1 are vulnerable to a Command Injection vulnerability due to missing input validation in the product.
network
low complexity
rsa CWE-78
7.5
2019-05-14 CVE-2018-14839 OS Command Injection vulnerability in LG N1A1 Firmware 3718.510
LG N1A1 NAS 3718.510 is affected by: Remote Command Execution.
network
low complexity
lg CWE-78
critical
9.8
2019-05-13 CVE-2018-19990 OS Command Injection vulnerability in D-Link Dir-822 Firmware 202Krb06
In the /HNAP1/SetWiFiVerifyAlpha message, the WPSPIN parameter is vulnerable, and the vulnerability affects D-Link DIR-822 B1 202KRb06 devices.
network
low complexity
d-link CWE-78
critical
9.8
2019-05-13 CVE-2018-19989 OS Command Injection vulnerability in multiple products
In the /HNAP1/SetQoSSettings message, the uplink parameter is vulnerable, and the vulnerability affects D-Link DIR-822 Rev.B 202KRb06 and DIR-822 Rev.C 3.10B06 devices.
network
low complexity
d-link dlink CWE-78
critical
9.8