Vulnerability Description
A Cross-site Scripting (XSS) vulnerability in Fortinet FortiManager 6.0.0, 5.6.4 and below versions, FortiAnalyzer 6.0.0, 5.6.4 and below versions allows inject Javascript code and HTML tags through the CN value of CA and CRL certificates via the import CA and CRL certificates feature.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Fortinet | Fortianalyzer Firmware | <= 5.6.4 |
| Fortinet | Fortimanager Firmware | <= 5.6.4 |
Related Weaknesses (CWE)
References
- http://www.securitytracker.com/id/1041246Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1041247Third Party AdvisoryVDB Entry
- https://fortiguard.com/advisory/FG-IR-17-305Vendor Advisory
- http://www.securitytracker.com/id/1041246Third Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1041247Third Party AdvisoryVDB Entry
- https://fortiguard.com/advisory/FG-IR-17-305Vendor Advisory
FAQ
What is CVE-2017-17541?
CVE-2017-17541 is a vulnerability with a CVSS score of 6.1 (MEDIUM). A Cross-site Scripting (XSS) vulnerability in Fortinet FortiManager 6.0.0, 5.6.4 and below versions, FortiAnalyzer 6.0.0, 5.6.4 and below versions allows inject Javascript code and HTML tags through t...
How severe is CVE-2017-17541?
CVE-2017-17541 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-17541?
Check the references section above for vendor advisories and patch information. Affected products include: Fortinet Fortianalyzer Firmware, Fortinet Fortimanager Firmware.