CISA urges devs to weed out OS command injection vulnerabilities

Share:

​CISA and the FBI urged software companies on Wednesday to review their products and eliminate path OS command injection vulnerabilities before shipping.

The advisory was released in response to recent attacks that exploited multiple OS command injection security flaws (CVE-2024-20399, CVE-2024-3400, and CVE-2024-21887) to compromise Cisco, Palo Alto, and Ivanti network edge devices.

Velvet Ant, the Chinese state-sponsored threat actor that coordinated these attacks, deployed custom malware to gain persistence on hacked devices as part of a cyber espionage campaign.

“OS command injection vulnerabilities arise when manufacturers fail to properly validate and sanitize user input when constructing commands to execute on the underlying OS,” today’s joint advisory explains.

“Designing and developing software that trusts user input without proper validation or sanitization can allow threat actors to execute malicious commands, putting customers at risk.”

CISA advises developers to implement well-known mitigations to prevent OS command injection vulnerabilities at scale while designing and developing software products:

  • Use built-in library functions that separate commands from their arguments whenever possible instead of constructing raw strings fed into a general-purpose system command.
  • Use input parameterization to keep data separate from commands; validate and sanitize all user-supplied input.
  • Limit the parts of commands constructed by user input to only what is necessary.

Tech leaders should be actively involved in the software development process. They can do this by ensuring that the software uses functions that generate commands safely while preserving the command’s intended syntax and arguments.

Additionally, they should review threat models, use modern component libraries, conduct code reviews, and implement rigorous product testing to ensure the quality and security of their code throughout the development lifecycle.

 

“OS command injection vulnerabilities have long been preventable by clearly separating user input from the contents of a command. Despite this finding, OS command injection vulnerabilities—many of which result from CWE-78—are still a prevalent class of vulnerability,” CISA and the FBI added.

“CISA and FBI urge CEOs and other business leaders at technology manufacturers to request their technical leaders to analyze past occurrences of this class of defect and develop a plan to eliminate them in the future.”

OS command injection security bugs took the fifth spot in MITRE’s top 25 most dangerous software weaknesses, surpassed only by out-of-bounds write, cross-site scripting, SQL injection, and use-after-free flaws.

In May and March, two other “Secure by Design” alerts urged tech executives and software developers to weed out path traversal and SQL injection (SQLi) security vulnerabilities.

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
6:57 pm, May 11, 2025
weather icon 22°C
L: 21° | H: 23°
scattered clouds
Humidity: 43 %
Pressure: 1008 mb
Wind: 7 mph ESE
Wind Gust: 14 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 47%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 5:14 am
Sunset: 8:39 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
21° | 23°°C 0.2 mm 20% 8 mph 52 % 1008 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
12° | 19°°C 1 mm 100% 9 mph 90 % 1015 mb 0 mm/h
Tue May 13 10:00 pm
weather icon
13° | 22°°C 0.5 mm 50% 12 mph 87 % 1020 mb 0 mm/h
Wed May 14 10:00 pm
weather icon
10° | 22°°C 0 mm 0% 9 mph 72 % 1023 mb 0 mm/h
Thu May 15 10:00 pm
weather icon
9° | 19°°C 0 mm 0% 10 mph 76 % 1027 mb 0 mm/h
Today 7:00 pm
weather icon
20° | 22°°C 0 mm 0% 8 mph 43 % 1008 mb 0 mm/h
Today 10:00 pm
weather icon
17° | 20°°C 0.2 mm 20% 4 mph 52 % 1008 mb 0 mm/h
Tomorrow 1:00 am
weather icon
14° | 17°°C 0 mm 0% 4 mph 68 % 1009 mb 0 mm/h
Tomorrow 4:00 am
weather icon
12° | 12°°C 0.36 mm 36% 3 mph 87 % 1010 mb 0 mm/h
Tomorrow 7:00 am
weather icon
13° | 13°°C 0.23 mm 23% 3 mph 90 % 1011 mb 0 mm/h
Tomorrow 10:00 am
weather icon
18° | 18°°C 0.32 mm 32% 4 mph 72 % 1012 mb 0 mm/h
Tomorrow 1:00 pm
weather icon
19° | 19°°C 1 mm 100% 9 mph 69 % 1012 mb 0 mm/h
Tomorrow 4:00 pm
weather icon
19° | 19°°C 1 mm 100% 8 mph 64 % 1012 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€92,415.51
0.54%
Ethereum(ETH)
€2,209.82
-0.24%
Tether(USDT)
€0.89
0.00%
XRP(XRP)
€2.10
-2.74%
Solana(SOL)
€152.50
-0.72%
USDC(USDC)
€0.89
0.00%
Dogecoin(DOGE)
€0.204001
-2.65%
Shiba Inu(SHIB)
€0.000014
-1.40%
Pepe(PEPE)
€0.000012
-0.06%
Peanut the Squirrel(PNUT)
€0.371709
23.15%
Scroll to Top