VDB

CVE-2024-27785

CVE-2024-27785 PUBLISHED CVSS 5.099999904632568 MEDIUM

An improper neutralization of formula elements in a CSV File vulnerability [CWE-1236] in FortiAIOps version 2.0.0 may allow a remote authenticated attacker to execute arbitrary commands on a client's workstation via poisoned CSV reports.

EPSS 0.64% · 70.9th percentile

Risk Scores

CVSS v3.1
5.099999904632568
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:L/A:L/E:P/RL:U/RC:C
EPSS Score
0.64%
70.9th percentile

Affected Products

VendorProductVersions
fortinetfortiaiops2.0.0
FortinetFortiAIOps2.0.0

Timeline

  • Jul 9, 2024 CVE Published
  • Jul 9, 2024 PoC Published
  • Jul 10, 2024 EPSS Score
  • Aug 1, 2024 EPSS Score
  • Aug 23, 2024 EPSS Score
  • Sep 14, 2024 EPSS Score
  • Oct 4, 2024 Coalition ESS Score
  • Oct 6, 2024 EPSS Score
  • Oct 28, 2024 EPSS Score
  • Nov 19, 2024 EPSS Score
  • Dec 12, 2024 EPSS Score
  • Jan 25, 2025 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›