CVE-2024-47572: Critical severity fortinet fortisoar imap connector vulnerability
Published Jan 14, 2025
·Updated
An improper neutralization of formula elements in a csv file in Fortinet FortiSOAR 7.2.1 through 7.4.1 allows attacker to execute unauthorized code or commands via manipulating csv file
Affected Software
4 affected components
Fortinet FortiSOAR>=7.2.1<=7.4.1
Fortinet FortiSOAR>=7.2.1<=7.2.2
Fortinet FortiSOAR>=7.3.0<7.3.3
Fortinet FortiSOAR>=7.4.0<7.4.2
Remediation
Information
Please upgrade to FortiSOAR version 7.4.2 or above
Please upgrade to FortiSOAR version 7.3.3 or above
Event History
Jan 14, 2025
CVE Published
via MITRE·02:09 PM
Data Sourced
via MITRE·02:09 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-47572?
CVE-2024-47572 has been rated as a high severity vulnerability.
2
How do I fix CVE-2024-47572?
To fix CVE-2024-47572, upgrade Fortinet FortiSOAR to version 7.4.2 or later.
3
What kind of attacks can exploit CVE-2024-47572?
CVE-2024-47572 can be exploited to execute unauthorized code or commands through a manipulated CSV file.
4
Which versions of Fortinet FortiSOAR are affected by CVE-2024-47572?
CVE-2024-47572 affects Fortinet FortiSOAR versions 7.2.1 through 7.4.1.
5
What is the impact of CVE-2024-47572 on Fortinet FortiSOAR?
The impact of CVE-2024-47572 is the potential execution of unauthorized code or commands due to improper neutralization of formula elements.