A CSV injection vulnerability in Automation Anywhere Automation 360 version 21094 allows attackers to execute arbitrary code via a crafted payload. NOTE: Automation Anywhere disputes this report, arguing the attacker executes everything from the client side and does not attack the Control Room. The payload is being injected in the http Response from the client-side, so the owner of the Response and payload is the end user in this case. They contend that the server's security controls have no impact or role to play in this situation and therefore this is not a valid vulnerability.
History

Tue, 03 Sep 2024 21:15:00 +0000

Type Values Removed Values Added
Description A CSV injection vulnerability in Automation Anywhere Automation 360 version 21094 allows attackers to execute arbitrary code via a crafted payload. A CSV injection vulnerability in Automation Anywhere Automation 360 version 21094 allows attackers to execute arbitrary code via a crafted payload. NOTE: Automation Anywhere disputes this report, arguing the attacker executes everything from the client side and does not attack the Control Room. The payload is being injected in the http Response from the client-side, so the owner of the Response and payload is the end user in this case. They contend that the server's security controls have no impact or role to play in this situation and therefore this is not a valid vulnerability.

Thu, 08 Aug 2024 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Automationanywhere
Automationanywhere automation 360
Weaknesses CWE-1236
CPEs cpe:2.3:a:automationanywhere:automation_360:21094:*:*:*:*:*:*:*
Vendors & Products Automationanywhere
Automationanywhere automation 360
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2024-08-06T00:00:00

Updated: 2024-09-03T21:02:39.796265

Reserved: 2024-07-18T00:00:00

Link: CVE-2024-41226

cve-icon Vulnrichment

Updated: 2024-08-08T14:06:17.201Z

cve-icon NVD

Status : Modified

Published: 2024-08-06T14:16:04.240

Modified: 2024-09-03T21:15:15.923

Link: CVE-2024-41226

cve-icon Redhat

No data.