CVE-2024-25007
CVSS V2 None
CVSS V3 None
Description
Ericsson Network Manager (ENM), versions prior to 23.1, contains a vulnerability in the export function of application log where Improper Neutralization of Formula Elements in a CSV File can lead to code execution or information disclosure. There is limited impact to integrity and availability. The attacker on the adjacent network with administration access can exploit the vulnerability.
Overview
- CVE ID
- CVE-2024-25007
- Assigner
- ERIC
- Vulnerability Status
- PUBLISHED
- Published Version
- 2024-04-04T18:25:21.681Z
- Last Modified Date
- 2024-04-04T19:07:37.177Z
Weakness Enumerations
References
Reference URL | Reference Tags |
---|---|
https://www.ericsson.com/en/about-us/security/psirt/security-bulletin--ericsson-network-manager-march-2024 |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2024-25007 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-25007 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-06-26 13:10:52 | Added to TrackCVE |