Improper Neutralization of Formula Elements in Fortinet FortiAnalyzer
CVE-2023-25611

4MEDIUM

Key Information:

Vendor

Fortinet

Vendor
CVE Published:
7 March 2023

What is CVE-2023-25611?

A vulnerability exists in Fortinet FortiAnalyzer that allows a local attacker to potentially execute unauthorized code or commands. This exploitation occurs through the improper handling of formula elements in CSV files. Attackers can manipulate spreadsheet formulas injected into macro names, leading to unintended execution of arbitrary code. Users of affected FortiAnalyzer versions should review security practices and apply necessary patches to mitigate the risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

FortiAnalyzer 7.2.0 <= 7.2.1

FortiAnalyzer 7.0.0 <= 7.0.5

FortiAnalyzer 6.4.0 <= 6.4.9

References

CVSS V3.1

Score:
4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.