CVE-2024-27785
An improper neutralization of formula elements in a CSV File [CWE-1236] vulnerability in Fortinet FortiAIOps 2.0.0 may allow a remote authenticated attacker to execute arbitrary commands on a client's
Exploited
Not listed
EPSS
0.004
35.4th percentile
Discovered by
Vendor
Vendor advisory field
Published
Jul 9, 2024
Assigned by fortinet
Description
An improper neutralization of formula elements in a CSV File [CWE-1236] vulnerability in Fortinet FortiAIOps 2.0.0 may allow a remote authenticated attacker to execute arbitrary commands on a client's workstation via poisoned CSV reports.
Weakness: CWE-1236
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Fortinet | FortiAIOps | Network & Security Management | cna-assigner |
Vendor-reported products (1)
- Fortinet · FortiAIOps
Credit
Internally discovered and reported by Shripal Rawal of Fortinet PSIRT team.
Vendor remediation
Upgrade to FortiAIOps version 2.0.1 or above