First published: Tue Mar 07 2023(Updated: )
A improper neutralization of formula elements in a CSV file vulnerability in Fortinet FortiAnalyzer 6.4.0 - 6.4.9, 7.0.0 - 7.0.5, and 7.2.0 - 7.2.1 allows local attacker to execute unauthorized code or commands via inserting spreadsheet formulas in macro names.
Credit: psirt@fortinet.com
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet FortiAnalyzer | >=6.4.0<7.0.6 | |
Fortinet FortiAnalyzer | >=7.2.0<7.2.2 | |
Fortinet FortiAnalyzer | >=7.2.0<=7.2.1 | |
Fortinet FortiAnalyzer | >=7.0.0<=7.0.6 | |
Fortinet FortiAnalyzer | >=6.4 |
Please upgrade to FortiAnalyzer version 7.2.2 or above Please upgrade to FortiAnalyzer version 7.0.6 or above
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-25611.
The severity of CVE-2023-25611 is high with a severity value of 7.3.
Fortinet FortiAnalyzer versions 6.4.0 - 6.4.9, 7.0.0 - 7.0.5, and 7.2.0 - 7.2.1 are affected by CVE-2023-25611.
A local attacker can exploit CVE-2023-25611 by inserting spreadsheet formulas in macro names in a CSV file, allowing them to execute unauthorized code or commands.
Update your Fortinet FortiAnalyzer to versions 7.0.6 or newer for versions 6.4.0 - 6.4.9, or to versions 7.2.2 or newer for versions 7.0.0 - 7.0.5 and 7.2.0 - 7.2.1.