Vulnerabilities > Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

DATE CVE VULNERABILITY TITLE RISK
2023-04-05 CVE-2023-20153 OS Command Injection vulnerability in Cisco Identity Services Engine 3.2
Multiple vulnerabilities in specific Cisco Identity Services Engine (ISE) CLI commands could allow an authenticated, local attacker to perform command injection attacks on the underlying operating system and elevate privileges to root.
local
low complexity
cisco CWE-78
6.7
2023-04-05 CVE-2023-20128 OS Command Injection vulnerability in Cisco Rv320 Firmware and Rv325 Firmware
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV320 and RV325 Dual Gigabit WAN VPN Routers could allow an authenticated, remote attacker to inject and execute arbitrary commands on the underlying operating system of an affected device.
network
low complexity
cisco CWE-78
7.2
2023-04-05 CVE-2023-20152 OS Command Injection vulnerability in Cisco Identity Services Engine 3.2
Multiple vulnerabilities in specific Cisco Identity Services Engine (ISE) CLI commands could allow an authenticated, local attacker to perform command injection attacks on the underlying operating system and elevate privileges to root.
local
low complexity
cisco CWE-78
6.7
2023-04-05 CVE-2023-20022 OS Command Injection vulnerability in Cisco Identity Services Engine 3.2
Multiple vulnerabilities in specific Cisco Identity Services Engine (ISE) CLI commands could allow an authenticated, local attacker to perform command injection attacks on the underlying operating system and elevate privileges to root.
local
low complexity
cisco CWE-78
6.7
2023-04-05 CVE-2023-20023 OS Command Injection vulnerability in Cisco Identity Services Engine 3.2
Multiple vulnerabilities in specific Cisco Identity Services Engine (ISE) CLI commands could allow an authenticated, local attacker to perform command injection attacks on the underlying operating system and elevate privileges to root.
local
low complexity
cisco CWE-78
6.7
2023-04-05 CVE-2023-20021 OS Command Injection vulnerability in Cisco Identity Services Engine 3.2
Multiple vulnerabilities in specific Cisco Identity Services Engine (ISE) CLI commands could allow an authenticated, local attacker to perform command injection attacks on the underlying operating system and elevate privileges to root.
local
low complexity
cisco CWE-78
6.7
2023-04-04 CVE-2023-26921 OS Command Injection vulnerability in Quectel Ag550Qcn Firmware
OS Command Injection vulnerability in quectel AG550QCN allows attackers to execute arbitrary commands via ql_atfwd.
network
low complexity
quectel CWE-78
critical
9.8
2023-03-31 CVE-2023-28726 OS Command Injection vulnerability in Panasonic Aiseg2 Firmware 2.80F/2.93A
Panasonic AiSEG2 versions 2.80F through 2.93A allows remote attackers to execute arbitrary OS commands.
network
low complexity
panasonic CWE-78
8.8
2023-03-29 CVE-2022-27647 OS Command Injection vulnerability in Netgear products
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6700v3 1.0.4.120_10.0.91 routers.
low complexity
netgear CWE-78
8.0
2023-03-29 CVE-2022-3210 OS Command Injection vulnerability in Dlink Dir-2150 Firmware
This vulnerability allows network-adjacent attackers to execute arbitrary commands on affected installations of D-Link DIR-2150 4.0.1 routers.
low complexity
dlink CWE-78
8.8