PT-2017-3086 · Fortinet · Fortios

Published

2017-06-15

·

Updated

2017-09-15

·

CVE-2017-7734

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Fortinet FortiOS versions 5.4.0 through 5.4.4
Description The issue allows attackers to execute unauthorized code or commands via the Comments field while saving Config Revisions, enabling remote attackers to perform Cross-Site Scripting attacks by entering malicious code in the Comments field and saving configuration changes.
Recommendations For Fortinet FortiOS versions 5.4.0 through 5.4.4, avoid using the Comments field when saving Config Revisions until a patch is available. As a temporary workaround, consider restricting access to the Config Revisions feature to minimize the risk of exploitation.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2017-02456
CVE-2017-7734

Affected Products

Fortios