logo

CISA urges devs to weed out OS command injection vulnerabilities

ID: 4739ba52-7195-526b-b3b7-0f8e38890a4c

STIX ID: report--4739ba52-7195-526b-b3b7-0f8e38890a4c

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2024-07-10

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

CISA and the FBI issued a joint advisory after Velvet Ant (a Chinese state‑sponsored group) exploited multiple OS command injection vulnerabilities (CVE-2024-20399, CVE-2024-3400, CVE-2024-21887) to compromise Cisco, Palo Alto, and Ivanti network edge devices and deploy custom malware for persistence; the advisory urges developers and leaders to adopt secure-by-design practices (input validation, parameterization, safe library functions, limited user-built command parts, code review and testing) to eliminate CWE-78 class flaws.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.