CVE-2017-17541
A Cross-site Scripting (XSS) vulnerability in Fortinet FortiManager 6.0.0, 5.6.4 and below versions, FortiAnalyzer 6.0.0, 5.6.4 and below versions allows inject Javascript code and HTML tags through the CN value of CA and CRL certificates via the import…
Does this matter?
Lower severity and a low EPSS score (0.87%). Track it; it rarely justifies an emergency change on its own.
Description
A Cross-site Scripting (XSS) vulnerability in Fortinet FortiManager 6.0.0, 5.6.4 and below versions, FortiAnalyzer 6.0.0, 5.6.4 and below versions allows inject Javascript code and HTML tags through the CN value of CA and CRL certificates via the import CA and CRL certificates feature.
- CVSS 3.0
- 6.1 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.87% probability · 57th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- fortinet/fortianalyzer firmware · fortinet/fortimanager firmware
- Source
- psirt@fortinet.com
References
- http://www.securitytracker.com/id/1041246Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1041247Third Party Advisory, VDB Entry
- https://fortiguard.com/advisory/FG-IR-17-305Vendor Advisory
- http://www.securitytracker.com/id/1041246Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1041247Third Party Advisory, VDB Entry
- https://fortiguard.com/advisory/FG-IR-17-305Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.