First published: Tue Sep 07 2021(Updated: )
An improper neutralization of formula elements in a csv file in Fortinet FortiManager version 6.4.3 and below, 6.2.7 and below allows attacker to execute arbitrary commands via crafted IPv4 field in policy name, when exported as excel file and opened unsafely on the victim host.
Credit: psirt@fortinet.com
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiManager | <6.2.8 | |
Fortinet FortiManager | >=6.4.0<6.4.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-24016 is an vulnerability in Fortinet FortiManager version 6.4.3 and below, 6.2.7 and below that allows an attacker to execute arbitrary commands via a crafted IPv4 field in a policy name when exported as an Excel file and opened unsafely on the victim host.
CVE-2021-24016 has a severity rating of 6.3, which is classified as critical.
CVE-2021-24016 affects Fortinet FortiManager versions 6.4.3 and below, 6.2.7 and below.
An attacker can exploit CVE-2021-24016 by crafting a malicious IPv4 field in a policy name, exporting it as an Excel file, and tricking the victim into opening it unsafely.
Fortinet has released a fix for CVE-2021-24016 in FortiManager version 6.4.4 and FortiManager version 6.2.8.