CWE-77
MITRE ↗Improper Neutralization of Special Elements used in a Command (Command Injection)
An issue was discovered in Tesla Motors Model S automobile, all firmware versions before version 7.1 (2.36.31) with web
EMC RecoverPoint versions before 4.4.1.1 and EMC RecoverPoint for Virtual Machines versions before 5.0 are affected by m
A vulnerability in the CLI command-parsing code of Cisco Meeting Server could allow an authenticated, local attacker to
A vulnerability in the debug interface of Cisco IP Phone 8800 series could allow an authenticated, local attacker to exe
A vulnerability in the CLI of Cisco NX-OS System Software could allow an authenticated, local attacker to perform a comm
A vulnerability in certain system script files that are installed at boot time on Cisco Application Policy Infrastructur
EMC Documentum D2 version 4.5 and EMC Documentum D2 version 4.6 has a DQL Injection Vulnerability that could potentially
A vulnerability in the CLI of Cisco Firepower Extensible Operating System (FXOS) and NX-OS System Software could allow a
A vulnerability in the CLI of Cisco NX-OS System Software could allow an authenticated, local attacker to perform a comm
A vulnerability in the CLI of Cisco NX-OS System Software could allow an authenticated, local attacker to perform a comm
A vulnerability in the CLI of Cisco NX-OS System Software could allow an authenticated, local attacker to perform a comm
IBM Maximo Asset Management 7.5 and 7.6 could allow an authenticated user to inject commands into work orders that could
A command injection vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pa
In Sophos Web Appliance (SWA) before 4.3.1.2, a section of the machine's interface responsible for generating reports wa
Frequently Asked Questions
What is CWE-77?
CWE-77 (Improper Neutralization of Special Elements used in a Command (Command Injection)) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-77?
There are 4,365 CVE records associated with CWE-77 in our database. Of these, 1041 are critical severity, 1473 are high severity, and 1080 are medium severity.
How can I protect against CWE-77 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-77 using AI-powered security agents.
Detect CWE-77 Vulnerabilities
CyberStrike's AI agents automatically detect improper neutralization of special elements used in a command (command injection) vulnerabilities across your infrastructure.
Get Started