CVE-2024-47572
An improper neutralization of formula elements in a csv file in Fortinet FortiSOAR 7.2.1 through 7.4.1 allows attacker to execute unauthorized code or commands via manipulating csv file
Severity
High 8.3
CVSS 3.1
Exploited
Not listed
EPSS
0.006
46.5th percentile
Discovered by
Vendor
Vendor advisory field
Published
Jan 14, 2025
Assigned by fortinet
Description
An improper neutralization of formula elements in a csv file in Fortinet FortiSOAR 7.2.1 through 7.4.1 allows attacker to execute unauthorized code or commands via manipulating csv file
Weakness: CWE-1236
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Fortinet | FortiSOAR | SIEM & Log Management | cna-assigner |
Vendor-reported products (1)
- Fortinet · FortiSOAR
Credit
Internally discovered and reported by Hritik Sateesh from Burnaby InfoSec team.
Vendor remediation
Please upgrade to FortiSOAR version 7.4.2 or above Please upgrade to FortiSOAR version 7.3.3 or above