Vulnerabilities > Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

DATE CVE VULNERABILITY TITLE RISK
2018-10-05 CVE-2018-15368 OS Command Injection vulnerability in Cisco IOS XE 15.4(3)S
A vulnerability in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to gain access to the underlying Linux shell of an affected device and execute arbitrary commands with root privileges on the device.
local
low complexity
cisco CWE-78
6.7
2018-10-05 CVE-2018-0481 OS Command Injection vulnerability in Cisco IOS XE 15.3(3)S3.16/16.7.1/16.7(1)
A vulnerability in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to execute commands on the underlying Linux shell of an affected device with root privileges.
local
low complexity
cisco CWE-78
6.7
2018-10-05 CVE-2018-0477 OS Command Injection vulnerability in Cisco IOS XE 15.3(3)S3.16/16.7.1/16.7(1)
A vulnerability in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to execute commands on the underlying Linux shell of an affected device with root privileges.
local
low complexity
cisco CWE-78
6.7
2018-10-05 CVE-2018-0453 OS Command Injection vulnerability in Cisco Firepower Threat Defense
A vulnerability in the Sourcefire tunnel control channel protocol in Cisco Firepower System Software running on Cisco Firepower Threat Defense (FTD) sensors could allow an authenticated, local attacker to execute specific CLI commands with root privileges on the Cisco Firepower Management Center (FMC), or through Cisco FMC on other Firepower sensors and devices that are controlled by the same Cisco FMC.
local
low complexity
cisco CWE-78
8.2
2018-10-05 CVE-2018-0433 OS Command Injection vulnerability in Cisco products
A vulnerability in the command-line interface (CLI) in the Cisco SD-WAN Solution could allow an authenticated, local attacker to inject arbitrary commands that are executed with root privileges.
local
low complexity
cisco CWE-78
7.8
2018-10-05 CVE-2018-0432 OS Command Injection vulnerability in Cisco products
A vulnerability in the error reporting feature of the Cisco SD-WAN Solution could allow an authenticated, remote attacker to gain elevated privileges on an affected device.
network
low complexity
cisco CWE-78
8.8
2018-10-05 CVE-2018-0424 OS Command Injection vulnerability in Cisco Rv110W Firmware, Rv130W Firmware and Rv215W Firmware
A vulnerability in the web-based management interface of the Cisco RV110W Wireless-N VPN Firewall, Cisco RV130W Wireless-N Multifunction VPN Router, and Cisco RV215W Wireless-N VPN Router could allow an authenticated, remote attacker to execute arbitrary commands.
network
low complexity
cisco CWE-78
8.8
2018-10-02 CVE-2018-17787 OS Command Injection vulnerability in D-Link Dir-823G Firmware
On D-Link DIR-823G devices, the GoAhead configuration allows /HNAP1 Command Injection via shell metacharacters in the POST data, because this data is sent directly to the "system" library function.
network
low complexity
d-link CWE-78
critical
9.8
2018-10-01 CVE-2018-17867 OS Command Injection vulnerability in Dasannetworks H660Gw Firmware
The Port Forwarding functionality on DASAN H660GW devices allows remote attackers to execute arbitrary code via shell metacharacters in the cgi-bin/adv_nat_virsvr.asp Addr parameter (aka the Local IP Address field).
network
low complexity
dasannetworks CWE-78
7.2
2018-09-28 CVE-2018-9077 OS Command Injection vulnerability in Lenovo Lenovoemc Firmware 4.1.402.34662
For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, when changing the name of a share, an attacker can craft a command injection payload using backtick "``" characters in the share : name parameter.
network
high complexity
lenovo CWE-78
8.1