CVE-2021-24016
published 2021-09-30CVE-2021-24016: An improper neutralization of formula elements in a csv file in Fortinet FortiManager version 6.4.3 and below, 6.2.7 and below allows attacker to execute…
PriorityP429medium6.3CVSS 3.1
AVLACHPRHUIRSUCHIHAH
EPSS
0.49%
38.8th percentile
An improper neutralization of formula elements in a csv file in Fortinet FortiManager version 6.4.3 and below, 6.2.7 and below allows attacker to execute arbitrary commands via crafted IPv4 field in policy name, when exported as excel file and opened unsafely on the victim host.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortimanager | < 6.2.8 | 6.2.8 |
| fortinet | fortimanager | — | — |
| fortinet | fortimanager | >= 6.4.0 < 6.4.4 | 6.4.4 |
| fortinet | fortinet | — | — |
| fortinet | fortinet_fortimanager | — | — |
CVSS provenance
nvdv3.16.3MEDIUMCVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Fortinet
An improper neutralization of formula elements in a csv file in Fortinet FortiManager version 6.4.3 and below, 6.2.7 and...
vendor_fortinet·2021-09-30·CVSS 3.7
CVE-2021-24016 [LOW] CWE-1236 An improper neutralization of formula elements in a csv file in Fortinet FortiManager version 6.4.3 and below, 6.2.7 and...
FG-IR-20-190: An improper neutralization of formula elements in a csv file in Fortinet FortiManager version 6.4.3 and below, 6.2.7 and...
An improper neutralization of formula elements in a csv file in Fortinet FortiManager version 6.4.3 and below, 6.2.7 and below allows attacker to execute arbitrary commands via crafted IPv4 field in policy name, when exported as excel file and opened unsafely on the victim host.
CVEs: CVE-2021-24016
CWEs: CWE-1236
CVSS: 3.7 (low)
Affected products: FortiManager, Fortinet
GHSA
GHSA-3xr4-xcg2-6xq7: An improper neutralization of formula elements in a csv file in Fortinet FortiManager version 6
ghsa_unreviewed·2022-05-24
CVE-2021-24016 [HIGH] CWE-1236 GHSA-3xr4-xcg2-6xq7: An improper neutralization of formula elements in a csv file in Fortinet FortiManager version 6
An improper neutralization of formula elements in a csv file in Fortinet FortiManager version 6.4.3 and below, 6.2.7 and below allows attacker to execute arbitrary commands via crafted IPv4 field in policy name, when exported as excel file and opened unsafely on the victim host.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-09-30
Published