Ericsson Network Manager (ENM), versions prior to 23.1, contains a vulnerability in the export function of application log where Improper Neutralization of Formula Elements in a CSV File can lead to code execution or information disclosure. There is limited impact to integrity and availability. The attacker on the adjacent network with administration access can exploit the vulnerability.
Use CWE-1236, Ericsson vendor hub and Network Manager product page to widen CVE-2024-25007 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2023-39909, CVE-2025-27258 and CVE-2022-46408 for nearby disclosures in the same product family. Additional editorial context is available in Why “Low” and “Medium” CVEs Still Breach Networks.