CVE-2021-1474Improper Neutralization of Formula Elements in a CSV File in Cisco Umbrella Insights Virtual Appliance

Severity
8.6HIGHNVD
CNA6.5
EPSS
0.3%
top 43.81%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 8
Latest updateMay 24

Description

Multiple vulnerabilities in the Admin audit log export feature and Scheduled Reports feature of Cisco Umbrella could allow an authenticated, remote attacker to perform formula and link injection attacks on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:HExploitability: 1.8 | Impact: 6.0

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-382q-3qj5-29mx: Multiple vulnerabilities in the Admin audit log export feature and Scheduled Reports feature of Cisco Umbrella could allow an authenticated, remote at2022-05-24
CVEList
Cisco Umbrella Link and CSV Formula Injection Vulnerabilities2021-04-08

📋Vendor Advisories

1
Cisco
Cisco Umbrella Link and CSV Formula Injection Vulnerabilities2021-04-07
CVE-2021-1474 — Cisco vulnerability | cvebase