Weaknesses of type CWE-77

2,829 results

Injeção de comando por entrada não neutralizada

O software monta um comando (shell, sistema operacional ou aplicação) usando dados recebidos de fora (entrada do usuário, API, banco de dados) sem remover ou neutralizar caracteres especiais que alteram a semântica do comando. Isso permite que um atacante injete comandos arbitrários que serão executados com as permissões da aplicação.

Example

Um script PHP que executa ping com o IP fornecido pelo usuário: `system('ping ' . $_GET['ip'])`. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, porque o ponto-e-vírgula não foi escapado e o shell interpreta dois comandos sequenciais.

How to mitigate

Use APIs seguras que não envolvem interpretação de shell (ex: ProcessBuilder em Java, subprocess.run com shell=False em Python). Se imperativo usar shell, valide com whitelist rigorosa (apenas caracteres alfanuméricos/IPs válidos) e escape com funções específicas da linguagem (escapeshellarg em PHP, shlex.quote em Python).

CVE-2018-0224—A vulnerability in the CLI of the Cisco StarOS operating system for Cisco ASR 5000 Series Aggregation Services Routers could allow an authenEPSS 0.5%CVE-2023-20075MEDIUMVulnerability in the CLI of Cisco Secure Email Gateway could allow an authenticated, remote attacker to execute arbitrary commands. TheseEPSS 0.5%CVE-2019-1607MEDIUMCisco NX-OS Software CLI Command Injection Vulnerability (CVE-2019-1607)EPSS 0.4%CVE-2019-1779MEDIUMCisco FXOS and NX-OS Software Command Injection VulnerabilityEPSS 0.4%CVE-2019-1610MEDIUMCisco NX-OS Software CLI Command Injection Vulnerability (CVE-2019-1610)EPSS 0.4%CVE-2019-1780MEDIUMCisco FXOS and NX-OS Software Command Injection VulnerabilityEPSS 0.4%CVE-2019-1611MEDIUMCisco FXOS and NX-OS Software CLI Command Injection Vulnerability (CVE-2019-1611)EPSS 0.4%CVE-2018-0433—Cisco SD-WAN Solution Command Injection VulnerabilityEPSS 0.4%CVE-2019-1608MEDIUMCisco NX-OS Software CLI Command Injection Vulnerability (CVE-2019-1608)EPSS 0.4%CVE-2019-12661MEDIUMCisco IOS XE Software Virtualization Manager CLI Command Injection VulnerabilityEPSS 0.4%CVE-2024-4639HIGHOnCell G3470A-LTE Series: Authenticated Command Injection via webDelIPSecEPSS 0.4%CVE-2023-20152MEDIUMCisco Identity Services Engine Command Injection VulnerabilitiesEPSS 0.4%CVE-2022-34383HIGHDell Edge Gateway 5200 (EGW) versions before 1.03.10 contain an operating system command injection vulnerability. A local malicious user mayEPSS 0.4%CVE-2023-20153MEDIUMCisco Identity Services Engine Command Injection VulnerabilitiesEPSS 0.4%CVE-2024-24909HIGHDell OpenManage Integration with Microsoft Windows Admin Center contains a Remote Code Execution vulnerability in the gateway plugin. A remoEPSS 0.4%CVE-2022-42906HIGHpowerline-gitstatus (aka Powerline Gitstatus) before 1.3.2 allows arbitrary code execution. git repositories can contain per-repository confEPSS 0.4%CVE-2024-53919HIGHAn injection vulnerability in Barco ClickShare CX-30/20, C-5/10, and ClickShare Bar Pro and Core models, running firmware before 2.21.1, allEPSS 0.4%CVE-2017-12352—A vulnerability in certain system script files that are installed at boot time on Cisco Application Policy Infrastructure Controllers could EPSS 0.4%CVE-2020-3176MEDIUMCisco Remote PHY Device Software Command Injection VulnerabilityEPSS 0.4%CVE-2019-1613MEDIUMCisco NX-OS Software CLI Command Injection Vulnerability (CVE-2019-1613)EPSS 0.4%