CVE-2024-25007: Ericsson Network Manager - Improper Neutralization of Formula Elements Vulnerability
Ericsson Network Manager (ENM), versions prior to 23.1, contains a vulnerability in the export function of application log where Improper Neutralization of Formula Elements in a CSV File can lead to code execution or information disclosure. There is limited impact to integrity and availability. The attacker on the adjacent network with administration access can exploit the vulnerability.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-25007?
CVE-2024-25007 has a moderate severity rating due to its potential for code execution and information disclosure.
How do I fix CVE-2024-25007?
To fix CVE-2024-25007, upgrade Ericsson Network Manager to version 23.1 or later.
What impact does CVE-2024-25007 have on my system?
CVE-2024-25007 may lead to code execution or unauthorized information disclosure affecting system security.
Which versions of Ericsson Network Manager are affected by CVE-2024-25007?
CVE-2024-25007 affects versions of Ericsson Network Manager prior to 23.1.
Can CVE-2024-25007 be exploited remotely?
CVE-2024-25007 can be exploited remotely through the export function of application logs.