VulnerabilityModified
CVE-2017-3126
An Open Redirect vulnerability in Fortinet FortiAnalyzer 5.4.0 through 5.4.2 and FortiManager 5.4.0 through 5.4.2 allows attacker to execute unauthorized code or commands via the next parameter.
MEDIUM 6.1EPSS 0.94%
Does this matter?
Lower severity and a low EPSS score (0.94%). Track it; it rarely justifies an emergency change on its own.
Description
An Open Redirect vulnerability in Fortinet FortiAnalyzer 5.4.0 through 5.4.2 and FortiManager 5.4.0 through 5.4.2 allows attacker to execute unauthorized code or commands via the next parameter.
- CVSS 3.0
- 6.1 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.94% probability · 59th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-601
- Affected
- fortinet/fortianalyzer firmware · fortinet/fortimanager firmware
- Source
- psirt@fortinet.com
References
- http://www.securityfocus.com/bid/98557Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1038539
- http://www.securitytracker.com/id/1038540
- https://fortiguard.com/psirt/FG-IR-17-014Vendor Advisory
- http://www.securityfocus.com/bid/98557Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1038539
- http://www.securitytracker.com/id/1038540
- https://fortiguard.com/psirt/FG-IR-17-014Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.