Vulnerabilities > Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

DATE CVE VULNERABILITY TITLE RISK
2018-03-28 CVE-2018-0169 OS Command Injection vulnerability in Cisco IOS 15.0(5.59)Emd
Multiple vulnerabilities in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to gain access to the underlying Linux shell of an affected device and execute arbitrary commands with root privileges on the device.
local
low complexity
cisco CWE-78
7.8
2018-03-27 CVE-2018-1238 OS Command Injection vulnerability in Dell EMC Scaleio
Dell EMC ScaleIO versions prior to 2.5, contain a command injection vulnerability in the Light Installation Agent (LIA).
network
high complexity
dell CWE-78
7.5
2018-03-22 CVE-2018-0539 OS Command Injection vulnerability in QQQ Systems Project QQQ Systems 2.24
QQQ SYSTEMS version 2.24 allows an attacker to execute arbitrary commands via unspecified vectors.
network
low complexity
qqq-systems-project CWE-78
critical
9.8
2018-03-15 CVE-2018-6231 OS Command Injection vulnerability in Trendmicro Smart Protection Server
A server auth command injection authentication bypass vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.3 and below could allow remote attackers to escalate privileges on vulnerable installations.
network
low complexity
trendmicro CWE-78
critical
9.8
2018-03-15 CVE-2018-6222 OS Command Injection vulnerability in Trendmicro Email Encryption Gateway 5.5
Arbitrary logs location in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to change location of log files and be manipulated to execute arbitrary commands and attain command execution on a vulnerable system.
local
low complexity
trendmicro CWE-78
7.8
2018-03-09 CVE-2018-0523 OS Command Injection vulnerability in Buffalo Wxr-1900Dhp2 Firmware 2.48
Buffalo WXR-1900DHP2 firmware Ver.2.48 and earlier allows an attacker to execute arbitrary OS commands via unspecified vectors.
low complexity
buffalo CWE-78
8.8
2018-03-08 CVE-2018-7890 OS Command Injection vulnerability in Zohocorp Manageengine Applications Manager
A remote code execution issue was discovered in Zoho ManageEngine Applications Manager before 13.6 (build 13640).
network
low complexity
zohocorp CWE-78
critical
9.8
2018-03-08 CVE-2017-7640 OS Command Injection vulnerability in Qnap Media Streaming Add-On
QNAP NAS application Media Streaming add-on version 421.1.0.2, 430.1.2.0, and earlier allows remote attackers to run arbitrary OS commands against the system with root privileges.
network
low complexity
qnap CWE-78
critical
9.8
2018-03-08 CVE-2018-0224 OS Command Injection vulnerability in Cisco Staros 21.3.0.67664/21.5.0
A vulnerability in the CLI of the Cisco StarOS operating system for Cisco ASR 5000 Series Aggregation Services Routers could allow an authenticated, local attacker to execute arbitrary commands with root privileges on an affected operating system.
local
low complexity
cisco CWE-78
6.7
2018-03-08 CVE-2018-0221 OS Command Injection vulnerability in Cisco Identity Services Engine
A vulnerability in specific CLI commands for the Cisco Identity Services Engine (ISE) could allow an authenticated, local attacker to perform command injection to the underlying operating system or cause a hang or disconnect of the user session.
local
low complexity
cisco CWE-78
6.7