Lucene search

K
cvelistSecomeaCVELIST:CVE-2020-29023
HistoryFeb 16, 2021 - 3:14 p.m.

CVE-2020-29023 CSV Formula Injection possible due to improper fields escaping in GateManager

2021-02-1615:14:57
CWE-116
Secomea
www.cve.org
3
secomea gatemanager
csv
arbitrary commands

CVSS3

3.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N

AI Score

4.2

Confidence

High

EPSS

0.001

Percentile

22.7%

Improper Encoding or Escaping of Output from CSV Report Generator of Secomea GateManager allows an authenticated administrator to generate a CSV file that may run arbitrary commands on a victim’s computer when opened in a spreadsheet program (like Excel). This issue affects: Secomea GateManager all versions prior to 9.3.

CNA Affected

[
  {
    "product": "GateManager",
    "vendor": "Secomea",
    "versions": [
      {
        "lessThan": "9.3",
        "status": "affected",
        "version": "all",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

3.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N

AI Score

4.2

Confidence

High

EPSS

0.001

Percentile

22.7%

Related for CVELIST:CVE-2020-29023