Vulnerabilities > CVE-2021-24016 - Improper Neutralization of Formula Elements in a CSV File vulnerability in Fortinet Fortimanager

047910
CVSS 9.3 - CRITICAL
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
fortinet
CWE-1236
critical

Summary

An improper neutralization of formula elements in a csv file in Fortinet FortiManager version 6.4.3 and below, 6.2.7 and below allows attacker to execute arbitrary commands via crafted IPv4 field in policy name, when exported as excel file and opened unsafely on the victim host.

Vulnerable Configurations

Part Description Count
Application
Fortinet
87