CVE-2025-11498
BaseFortify
Publication date: 2025-10-14
Last updated on: 2025-10-14
Assigner: Asea Brown Boveri Ltd. (ABB)
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| br_automation | system_diagnostics_manager | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-1236 | The product saves user-provided information into a Comma-Separated Value (CSV) file, but it does not neutralize or incorrectly neutralizes special elements that could be interpreted as a command when the file is opened by a spreadsheet product. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is an Improper Neutralization of Formula Elements in a CSV file within the System Diagnostics Manager (SDM) of B&R Automation Runtime versions before 6.4. It allows a remote attacker to inject malicious formula data into a generated CSV file. To exploit this, the attacker must create a malicious link that a user clicks, and then the user must manually open the resulting CSV file, which contains the injected formula.
How can this vulnerability impact me? :
The vulnerability can lead to the execution of malicious formulas when the CSV file is opened, potentially allowing attackers to perform unauthorized actions such as data manipulation or code execution within the context of the user's environment. This can compromise data integrity and security.