Falhas do tipo CWE-77

2.832 resultados

Injeção de comando

O software monta comandos do sistema ou de interpretadores (shell, SQL, etc.) usando dados que vêm de fora (entrada do usuário, requisição HTTP, arquivo) sem sanitizar ou sanitizando incorretamente caracteres especiais. Um atacante consegue 'fechar' o comando legítimo e injetar comandos arbitrários que serão executados com os mesmos privilégios da aplicação.

Exemplo

Um script que executa `ping` no endereço fornecido pelo usuário: `system('ping ' + user_input)`. Se o usuário digita `8.8.8.8; rm -rf /`, o comando executado vira dois: primeiro o ping, depois a deleção de arquivos. A maioria das CVEs de injeção de comando vêm deste padrão.

Como mitigar

Use APIs que aceitam argumentos como lista (não concatenação de strings) — ex: subprocess.run(['ping', user_input]) em Python ou parameterized queries em banco de dados. Se precisar de interpretador, valide rigorosamente a entrada com lista branca (aceita apenas IP/domínio válido) e evite shells intermediários.

CVE-2018-0224—A vulnerability in the CLI of the Cisco StarOS operating system for Cisco ASR 5000 Series Aggregation Services Routers could allow an authenEPSS 0.5%CVE-2023-20075MEDIUMVulnerability in the CLI of Cisco Secure Email Gateway could allow an authenticated, remote attacker to execute arbitrary commands. TheseEPSS 0.5%CVE-2019-1608MEDIUMCisco NX-OS Software CLI Command Injection Vulnerability (CVE-2019-1608)EPSS 0.4%CVE-2019-1607MEDIUMCisco NX-OS Software CLI Command Injection Vulnerability (CVE-2019-1607)EPSS 0.4%CVE-2019-1779MEDIUMCisco FXOS and NX-OS Software Command Injection VulnerabilityEPSS 0.4%CVE-2019-1780MEDIUMCisco FXOS and NX-OS Software Command Injection VulnerabilityEPSS 0.4%CVE-2019-1611MEDIUMCisco FXOS and NX-OS Software CLI Command Injection Vulnerability (CVE-2019-1611)EPSS 0.4%CVE-2018-0433—Cisco SD-WAN Solution Command Injection VulnerabilityEPSS 0.4%CVE-2019-1610MEDIUMCisco NX-OS Software CLI Command Injection Vulnerability (CVE-2019-1610)EPSS 0.4%CVE-2024-4639HIGHOnCell G3470A-LTE Series: Authenticated Command Injection via webDelIPSecEPSS 0.4%CVE-2019-12661MEDIUMCisco IOS XE Software Virtualization Manager CLI Command Injection VulnerabilityEPSS 0.4%CVE-2022-34383HIGHDell Edge Gateway 5200 (EGW) versions before 1.03.10 contain an operating system command injection vulnerability. A local malicious user mayEPSS 0.4%CVE-2023-20152MEDIUMCisco Identity Services Engine Command Injection VulnerabilitiesEPSS 0.4%CVE-2023-20153MEDIUMCisco Identity Services Engine Command Injection VulnerabilitiesEPSS 0.4%CVE-2024-24909HIGHDell OpenManage Integration with Microsoft Windows Admin Center contains a Remote Code Execution vulnerability in the gateway plugin. A remoEPSS 0.4%CVE-2022-42906HIGHpowerline-gitstatus (aka Powerline Gitstatus) before 1.3.2 allows arbitrary code execution. git repositories can contain per-repository confEPSS 0.4%CVE-2024-53919HIGHAn injection vulnerability in Barco ClickShare CX-30/20, C-5/10, and ClickShare Bar Pro and Core models, running firmware before 2.21.1, allEPSS 0.4%CVE-2020-3210MEDIUMCisco IOS Software for Cisco Industrial Routers Virtual Device Server CLI Command Injection VulnerabilityEPSS 0.4%CVE-2020-3176MEDIUMCisco Remote PHY Device Software Command Injection VulnerabilityEPSS 0.4%CVE-2019-1613MEDIUMCisco NX-OS Software CLI Command Injection Vulnerability (CVE-2019-1613)EPSS 0.4%