ZeroHour

CVE-2024-25007

CVSS 3.1
7.1 high
EPSS
<1%p37
Published
()
Modified
Description

Ericsson Network Manager (ENM), versions prior to 23.1, contains a vulnerability in the export function of application log where Improper Neutralization of Formula Elements in a CSV File can lead to code execution or information disclosure. There is limited impact to integrity and availability. The attacker on the adjacent network with administration access can exploit the vulnerability.

Vendors
ericsson
Products
network manager
Weakness
CWE-1236
Vector
CVSS:3.1/AV:A/AC:L/PR:H/UI:R/S:C/C:L/I:H/A:L

In the news

No ingested article mentions this CVE yet.