Vulnerability Description
A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiOS 6.0.7 - 6.0.15, 6.2.2 - 6.2.12, 6.4.0 - 6.4.9 and 7.0.0 - 7.0.3 allows a privileged attacker to execute unauthorized code or commands via storing malicious payloads in replacement messages.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Fortinet | Fortios | >= 6.0.7, <= 6.0.15 |
Related Weaknesses (CWE)
References
- https://fortiguard.com/psirt/FG-IR-21-248Vendor Advisory
- https://fortiguard.com/psirt/FG-IR-21-248Vendor Advisory
FAQ
What is CVE-2022-40680?
CVE-2022-40680 is a vulnerability with a CVSS score of 4.0 (MEDIUM). A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiOS 6.0.7 - 6.0.15, 6.2.2 - 6.2.12, 6.4.0 - 6.4.9 and 7.0.0 - 7.0.3 allows a privileged attacker ...
How severe is CVE-2022-40680?
CVE-2022-40680 has been rated MEDIUM with a CVSS base score of 4.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-40680?
Check the references section above for vendor advisories and patch information. Affected products include: Fortinet Fortios.