CVE-2024-25007: Ericsson Network Manager

High severity, CVSS 7.1. EPSS: 0.4% chance of exploitation in the next 30 days.

Ericsson Network Manager (ENM), versions prior to 23.1, contains a vulnerability in the export function of application log where Improper Neutralization of Formula Elements in a CSV File can lead to code execution or information disclosure. There is limited impact to integrity and availability. The attacker on the adjacent network with administration access can exploit the vulnerability.

Affected products

  • Ericsson Network Manager: before 23.1 (fixed in 23.1)

Published 2024-04-04. Last modified 2026-06-17.