Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-25007

Опубликовано: 04 апр. 2024
Источник: nvd
CVSS3: 7.1
EPSS Низкий

Описание

Ericsson Network Manager (ENM), versions prior to 23.1, contains a vulnerability in the export function of application log where Improper Neutralization of Formula Elements in a CSV File can lead to code execution or information disclosure. There is limited impact to integrity and availability. The attacker on the adjacent network with administration access can exploit the vulnerability.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:ericsson:network_manager:*:*:*:*:*:*:*:*
Версия до 23.1 (исключая)

EPSS

Процентиль: 17%
0.00054
Низкий

7.1 High

CVSS3

Дефекты

CWE-1236
CWE-1236

Связанные уязвимости

CVSS3: 7.1
github
почти 2 года назад

Ericsson Network Manager (ENM), versions prior to 23.1, contains a vulnerability in the export function of application log where Improper Neutralization of Formula Elements in a CSV File can lead to code execution or information disclosure. There is limited impact to integrity and availability. The attacker on the adjacent network with administration access can exploit the vulnerability.

EPSS

Процентиль: 17%
0.00054
Низкий

7.1 High

CVSS3

Дефекты

CWE-1236
CWE-1236