PT-2017-3086 · Fortinet · Fortios
Published
2017-06-15
·
Updated
2017-09-15
·
CVE-2017-7734
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Fortinet FortiOS versions 5.4.0 through 5.4.4
Description
The issue allows attackers to execute unauthorized code or commands via the
Comments field while saving Config Revisions, enabling remote attackers to perform Cross-Site Scripting attacks by entering malicious code in the Comments field and saving configuration changes.Recommendations
For Fortinet FortiOS versions 5.4.0 through 5.4.4, avoid using the
Comments field when saving Config Revisions until a patch is available.
As a temporary workaround, consider restricting access to the Config Revisions feature to minimize the risk of exploitation.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fortios