CVE-2024-25007

Published Apr 4, 2024

Last updated 7 months ago

Overview

Description
Ericsson Network Manager (ENM), versions prior to 23.1, contains a vulnerability in the export function of application log where Improper Neutralization of Formula Elements in a CSV File can lead to code execution or information disclosure. There is limited impact to integrity and availability. The attacker on the adjacent network with administration access can exploit the vulnerability.
Source
85b1779b-6ecd-4f52-bcc5-73eac4659dcf
NVD status
Analyzed

Risk scores

CVSS 3.1

Type
Primary
Base score
7.1
Impact score
5.3
Exploitability score
1.2
Vector string
CVSS:3.1/AV:A/AC:L/PR:H/UI:R/S:C/C:L/I:H/A:L
Severity
HIGH

Weaknesses

nvd@nist.gov
CWE-1236
85b1779b-6ecd-4f52-bcc5-73eac4659dcf
CWE-1236

Social media

Hype score
Not currently trending

Configurations