CVE-2024-47572

An improper neutralization of formula elements in a csv file in Fortinet FortiSOAR 7.2.1 through 7.4.1 allows attacker to execute unauthorized code or commands via manipulating csv file

Severity
High 8.3
CVSS 3.1
Exploited
Not listed
EPSS
0.006
46.5th percentile
Discovered by
Vendor
Vendor advisory field
Published
Jan 14, 2025
Assigned by fortinet

Description

An improper neutralization of formula elements in a csv file in Fortinet FortiSOAR 7.2.1 through 7.4.1 allows attacker to execute unauthorized code or commands via manipulating csv file

Weakness: CWE-1236

Affected products

Vendor Product Category Matched by
Fortinet FortiSOAR SIEM & Log Management cna-assigner
Vendor-reported products (1)
  • Fortinet · FortiSOAR

Credit

Internally discovered and reported by Hritik Sateesh from Burnaby InfoSec team.

Vendor remediation

Please upgrade to FortiSOAR version 7.4.2 or above Please upgrade to FortiSOAR version 7.3.3 or above

Something wrong here?