cbcvebase.
CVE-2023-47534
published 2024-03-12

CVE-2023-47534: A improper neutralization of formula elements in a csv file in Fortinet FortiClientEMS version 7.2.0 through 7.2.2, 7.0.0 through 7.0.10, 6.4.0 through 6.4.9…

high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
A improper neutralization of formula elements in a csv file in Fortinet FortiClientEMS version 7.2.0 through 7.2.2, 7.0.0 through 7.0.10, 6.4.0 through 6.4.9, 6.2.0 through 6.2.9, 6.0.0 through 6.0.8 allows attacker to execute unauthorized code or commands via specially crafted packets.

Affected

16 ranges
VendorProductVersion rangeFixed in
fortinetforticlient_endpoint_management_server6.0.0 – 6.0.8
fortinetforticlient_endpoint_management_server6.2.0 – 6.2.9
fortinetforticlient_endpoint_management_server6.4.0 – 6.4.9
fortinetforticlient_endpoint_management_server7.0.0 – 7.0.10
fortinetforticlient_endpoint_management_server7.2.0 – 7.2.2
fortinetforticlientems
fortinetforticlientems
fortinetforticlientems6.0.0 – 6.0.6
fortinetforticlientems6.2.0 – 6.2.4
fortinetforticlientems6.2.6 – 6.2.9
fortinetforticlientems6.4.0 – 6.4.4
fortinetforticlientems6.4.7 – 6.4.9
fortinetforticlientems7.0.0 – 7.0.10
fortinetforticlientems7.2.0 – 7.2.2
fortinetforticlientendpointmanagementserver
fortinetfortinet