Vulnerabilities > Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

DATE CVE VULNERABILITY TITLE RISK
2019-05-15 CVE-2019-3727 OS Command Injection vulnerability in Dell products
Dell EMC RecoverPoint versions prior to 5.1.3 and RecoverPoint for VMs versions prior to 5.2.0.2 contain an OS command injection vulnerability in the installation feature of Boxmgmt CLI.
local
low complexity
dell CWE-78
6.7
2019-05-15 CVE-2019-3725 OS Command Injection vulnerability in RSA Netwitness and Security Analytics
RSA Netwitness Platform versions prior to 11.2.1.1 and RSA Security Analytics versions prior to 10.6.6.1 are vulnerable to a Command Injection vulnerability due to missing input validation in the product.
network
low complexity
rsa CWE-78
critical
9.8
2019-05-14 CVE-2018-14839 OS Command Injection vulnerability in LG N1A1 Firmware 3718.510
LG N1A1 NAS 3718.510 is affected by: Remote Command Execution.
network
low complexity
lg CWE-78
critical
9.8
2019-05-13 CVE-2019-3702 OS Command Injection vulnerability in Lifesize products
A Remote Code Execution issue in the DNS Query Web UI in Lifesize Icon LS_RM3_3.7.0 (2421) allows remote authenticated attackers to execute arbitrary commands via a crafted DNS Query address field in a JSON API request.
network
low complexity
lifesize CWE-78
8.8
2019-05-13 CVE-2018-19990 OS Command Injection vulnerability in D-Link Dir-822 Firmware 202Krb06
In the /HNAP1/SetWiFiVerifyAlpha message, the WPSPIN parameter is vulnerable, and the vulnerability affects D-Link DIR-822 B1 202KRb06 devices.
network
low complexity
d-link CWE-78
critical
9.8
2019-05-13 CVE-2018-19989 OS Command Injection vulnerability in multiple products
In the /HNAP1/SetQoSSettings message, the uplink parameter is vulnerable, and the vulnerability affects D-Link DIR-822 Rev.B 202KRb06 and DIR-822 Rev.C 3.10B06 devices.
network
low complexity
d-link dlink CWE-78
critical
9.8
2019-05-13 CVE-2018-19988 OS Command Injection vulnerability in D-Link Dir-868L Firmware 2.05B02
In the /HNAP1/SetClientInfoDemo message, the AudioMute and AudioEnable parameters are vulnerable, and the vulnerabilities affect D-Link DIR-868L Rev.B 2.05B02 devices.
network
low complexity
d-link CWE-78
critical
9.8
2019-05-13 CVE-2018-19987 OS Command Injection vulnerability in multiple products
D-Link DIR-822 Rev.B 202KRb06, DIR-822 Rev.C 3.10B06, DIR-860L Rev.B 2.03.B03, DIR-868L Rev.B 2.05B02, DIR-880L Rev.A 1.20B01_01_i3se_BETA, and DIR-890L Rev.A 1.21B02_BETA devices mishandle IsAccessPoint in /HNAP1/SetAccessPointMode.
network
low complexity
d-link dlink CWE-78
critical
9.8
2019-05-13 CVE-2018-19986 OS Command Injection vulnerability in D-Link Dir-818Lw Firmware and Dir-822 Firmware
In the /HNAP1/SetRouterSettings message, the RemotePort parameter is vulnerable, and the vulnerability affects D-Link DIR-818LW Rev.A 2.05.B03 and DIR-822 B1 202KRb06 devices.
network
low complexity
d-link CWE-78
critical
9.8
2019-05-10 CVE-2018-7084 OS Command Injection vulnerability in multiple products
A command injection vulnerability is present that permits an unauthenticated user with access to the Aruba Instant web interface to execute arbitrary system commands within the underlying operating system.
network
low complexity
arubanetworks siemens CWE-78
critical
9.8