CVE-2021-1474 - Improper Neutralization of Formula Elements in a CSV File

Severity

86%

Complexity

18%

Confidentiality

100%

Multiple vulnerabilities in the Admin audit log export feature and Scheduled Reports feature of Cisco Umbrella could allow an authenticated, remote attacker to perform formula and link injection attacks on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.

CVSS 3.1 Base Score 8.6. CVSS Attack Vector: local. CVSS Attack Complexity: low. CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H).

CVSS 2.0 Base Score 6.8. CVSS Attack Vector: network. CVSS Attack Complexity: medium. CVSS Vector: (AV:N/AC:M/Au:N/C:P/I:P/A:P).

Demo Examples

Improper Neutralization of Formula Elements in a CSV File

CWE-1236

Hyperlinks or other commands can be executed when a cell begins with the formula identifier, '='


                    

=HYPERLINK(link_location, [friendly_name])

Stripping the leading equals sign, or simply not executing formulas from untrusted sources, impedes malicious activity.


                    

HYPERLINK(link_location, [friendly_name])

Overview

First reported 3 years ago

2021-04-08 04:15:00

Last updated 3 years ago

2021-04-19 14:28:00

Affected Software

Cisco Umbrella

Stay updated

ExploitPedia is constantly evolving. Sign up to receive a notification when we release additional functionality.

Get in touch

If you'd like to report a bug or have any suggestions for improvements then please do get in touch with us using this form. We will get back to you as soon as we can.