Vulnerability Description
An improper neutralization of input during web page Generation vulnerability [CWE-79] in FortiOS version 7.4.3 and below, version 7.2.7 and below, version 7.0.13 and below and FortiProxy version 7.4.3 and below, version 7.2.9 and below, version 7.0.16 and below web SSL VPN UI may allow a remote unauthenticated attacker to perform a Cross-Site Scripting attack via a malicious samba server.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Fortinet | Fortios | >= 6.4.0, < 7.0.14 |
| Fortinet | Fortiproxy | >= 7.0.0, < 7.0.17 |
Related Weaknesses (CWE)
References
- https://fortiguard.fortinet.com/psirt/FG-IR-23-485Vendor Advisory
FAQ
What is CVE-2024-26006?
CVE-2024-26006 is a vulnerability with a CVSS score of 7.5 (HIGH). An improper neutralization of input during web page Generation vulnerability [CWE-79] in FortiOS version 7.4.3 and below, version 7.2.7 and below, version 7.0.13 and below and FortiProxy version 7.4.3...
How severe is CVE-2024-26006?
CVE-2024-26006 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-26006?
Check the references section above for vendor advisories and patch information. Affected products include: Fortinet Fortios, Fortinet Fortiproxy.