CVE-2023-47534

CWE-12364 documents4 sources
Severity
8.8HIGH
EPSS
0.2%
top 51.88%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 12

Description

A improper neutralization of formula elements in a csv file in Fortinet FortiClientEMS version 7.2.0 through 7.2.2, 7.0.0 through 7.0.10, 6.4.0 through 6.4.9, 6.2.0 through 6.2.9, 6.0.0 through 6.0.8 allows attacker to execute unauthorized code or commands via specially crafted packets.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:HExploitability: 2.8 | Impact: 6.0

Affected Packages2 packages

CVEListV5fortinet/forticlientems7.2.07.2.2+7

🔴Vulnerability Details

2
GHSA
GHSA-452h-x3w8-jmmh: A improper neutralization of formula elements in a csv file in Fortinet FortiClientEMS version 72024-03-12
CVEList
CVE-2023-47534: A improper neutralization of formula elements in a csv file in Fortinet FortiClientEMS version 72024-03-12

📋Vendor Advisories

1
Fortinet
A improper neutralization of formula elements in a csv file in Fortinet FortiClientEMS version 7.2.0 through 7.2.2, 7.0...2024-03-12
CVE-2023-47534 (HIGH CVSS 8.8) | A improper neutralization of formul | cvebase.io