CVE-2020-29023: CSV Formula Injection possible due to improper fields escaping in GateManager
Improper Encoding or Escaping of Output from CSV Report Generator of Secomea GateManager allows an authenticated administrator to generate a CSV file that may run arbitrary commands on a victim's computer when opened in a spreadsheet program (like Excel). This issue affects: Secomea GateManager all versions prior to 9.3.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-29023?
CVE-2020-29023 is a vulnerability that allows an authenticated administrator to generate a CSV file that may run arbitrary commands on a victim's computer when opened in a spreadsheet program.
How does CVE-2020-29023 affect Secomea GateManager?
CVE-2020-29023 affects all versions of Secomea GateManager.
What is the severity of CVE-2020-29023?
CVE-2020-29023 has a severity rating of medium with a score of 3.5.
How can I fix CVE-2020-29023?
To fix CVE-2020-29023, it is recommended to update Secomea GateManager to the latest version available.
Where can I find more information about CVE-2020-29023?
You can find more information about CVE-2020-29023 on the Secomea website: https://www.secomea.com/support/cybersecurity-advisory/