CVE-2021-24016Improper Neutralization of Formula Elements in a CSV File in Fortinet Fortimanager

Severity
6.3MEDIUMNVD
CNA3.7
EPSS
0.1%
top 65.34%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 30
Latest updateMay 24

Description

An improper neutralization of formula elements in a csv file in Fortinet FortiManager version 6.4.3 and below, 6.2.7 and below allows attacker to execute arbitrary commands via crafted IPv4 field in policy name, when exported as excel file and opened unsafely on the victim host.

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:HExploitability: 0.3 | Impact: 5.9

Affected Packages2 packages

NVDfortinet/fortimanager6.4.06.4.4+1
CVEListV5fortinet/fortinet_fortimanagerFortiManager 6.4.3, 6.2.7

🔴Vulnerability Details

2
GHSA
GHSA-3xr4-xcg2-6xq7: An improper neutralization of formula elements in a csv file in Fortinet FortiManager version 62022-05-24
CVEList
CVE-2021-24016: An improper neutralization of formula elements in a csv file in Fortinet FortiManager version 62021-09-30

📋Vendor Advisories

1
Fortinet
An improper neutralization of formula elements in a csv file in Fortinet FortiManager version 6.4.3 and below, 6.2.7 and...2021-09-30
CVE-2021-24016 — Fortinet Fortimanager vulnerability | cvebase