FG-IR-20-190: Excel formula injection in P&O IPv4 Policy names Vulnerability
Published Sep 7, 2021
·Updated
An improper neutralization of formula elements vulnerability (CWE 1236) in FortiManager may allow a local authenticated privileged attacker to execute arbitrary shell code on the end-user's host via inserting CSV formula in the policy names. This is achieved once the user downloads and opens the configuration csv/xls file.
Affected Software
1 affected component
Fortinet FortiManager
Event History
Sep 7, 2021
Advisory Published
via FortiGuard·12:00 AM
Data Sourced
via FortiGuard·12:00 AM
DescriptionSeverityWeaknessAffected Software
Oct 25, 2024
Advisory Published
via FortiGuard·12:00 AM
Frequently Asked Questions
1
What is the severity of FG-IR-20-190?
The severity of FG-IR-20-190 is classified as high due to the potential for remote code execution.
2
How do I fix FG-IR-20-190?
To fix FG-IR-20-190, update your FortiManager to the latest version provided by Fortinet.
3
Who can exploit FG-IR-20-190?
FG-IR-20-190 can be exploited by local authenticated privileged attackers.
4
What is the impact of FG-IR-20-190?
The impact of FG-IR-20-190 allows an attacker to execute arbitrary shell code on the end-user's host.
5
What software is affected by FG-IR-20-190?
FG-IR-20-190 affects Fortinet FortiManager software.