Fallos del tipo CWE-78

4665 resultados

Injeção de Comando do Sistema Operacional

A aplicação constrói comandos do SO (shell, cmd.exe, etc.) usando dados de entrada do usuário ou de fontes externas sem validar ou sanitizar adequadamente. Um atacante consegue injetar metacaracteres especiais (como ;, |, &, `, $()) para executar comandos arbitrários além daqueles originalmente planejados.

Ejemplo

Uma API que executa `ping hostname` recebendo o hostname como parâmetro GET faz isso: `exec('ping ' + request.query.host)`. Um atacante passa `8.8.8.8; rm -rf /` e consegue deletar arquivos do servidor, não apenas fazer ping.

Cómo mitigar

Evite construir comandos concatenando strings com entrada externa — use bibliotecas que parametrizem comandos ou listas de argumentos (como execFile no Node.js, subprocess com lista em Python, ProcessBuilder em Java). Se for inevitável, valide contra uma whitelist rígida e, se disponível, use modo restrito do shell (sh -c com argumentos seguros) ou contenha a execução em sandbox/container.

CVE-2023-20021MEDIUMCisco Identity Services Engine Privilege Escalation VulnerabilitiesEPSS 0.4%CVE-2023-20022MEDIUMCisco Identity Services Engine Privilege Escalation VulnerabilitiesEPSS 0.4%CVE-2026-0309MEDIUMPAN-OS: Authenticated Command Injection in CLI with Luna HSM ConfigurationEPSS 0.4%CVE-2025-36245HIGHIBM InfoSphere Information Server command executionEPSS 0.4%CVE-2026-53534HIGHJabRef CAYW Sublime Text integration permits operating-system command injectionEPSS 0.4%CVE-2021-1584MEDIUMCisco Nexus 9000 Series Fabric Switches ACI Mode Privilege Escalation VulnerabilityEPSS 0.4%CVE-2019-1745HIGHCisco IOS XE Software Command Injection VulnerabilityEPSS 0.4%CVE-2026-79916CRITICALMaxKB AWS Bedrock model credential injection leads to remote code executionEPSS 0.4%CVE-2024-21821HIGHMultiple TP-LINK products allow a network-adjacent authenticated attacker with access to the product from the LAN port or Wi-Fi to execute aEPSS 0.4%CVE-2017-6796—A vulnerability in the USB-modem code of Cisco IOS XE Software running on Cisco ASR 920 Series Aggregation Services Routers could allow an aEPSS 0.4%CVE-2026-49402HIGHDeno: Command Injection via spawnSync & spawn on WindowsEPSS 0.4%CVE-2025-27078MEDIUMAuthenticated Remote Command Execution caused by Insecure Function Usage in System BinaryEPSS 0.4%CVE-2018-0115—A vulnerability in the CLI of the Cisco StarOS operating system for Cisco ASR 5000 Series routers could allow an authenticated, local attackEPSS 0.4%CVE-2020-3169MEDIUMCisco FXOS Software CLI Command Injection VulnerabilityEPSS 0.4%CVE-2024-54025MEDIUMAn improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiIsolatEPSS 0.4%CVE-2025-53868HIGHBIG-IP SCP and SFTP vulnerabilityEPSS 0.4%CVE-2026-65611MEDIUMShell Command Injection in nnnEPSS 0.4%CVE-2026-63725HIGHsysPass FileBackupService Authenticated OS Command Injection via Backup PathEPSS 0.4%CVE-2026-65612MEDIUMShell Command Injection in nnnEPSS 0.4%CVE-2023-34214HIGHSecond Order Command-injection Vulnerability in the Certificate-generation FunctionEPSS 0.4%