CVE-2024-27785

medium Fortinet
CVSS v3 Base Score
5.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:L/A:L
EPSS Score
0.6%
Exploitation probability in 30 days
Top 30% most likely to be exploited
Attack Characteristics
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Confidentiality
None
Integrity
Low
Availability
Low
Published: July 9, 2024 (673 days ago)
Last Modified: January 9, 2026
Vendor: Fortinet

Description

An improper neutralization of formula elements in a CSV File [CWE-1236] vulnerability in Fortinet FortiAIOps 2.0.0 may allow a remote authenticated attacker to execute arbitrary commands on a client's workstation via poisoned CSV reports.

CWE

CWE-1236

Affected Products

fortinet fortiaiops

References