CVE-2017-17541
CVE-2017-17541
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS —EPSS 0.9%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
16 Jul 2018Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A Cross-site Scripting (XSS) vulnerability in Fortinet FortiManager 6.0.0, 5.6.4 and below versions, FortiAnalyzer 6.0.0, 5.6.4 and below versions allows inject Javascript code and HTML tags through the CN value of CA and CRL certificates via the import CA and CRL certificates feature.
Affected products
Fortinet · Fortinet FortiManager, FortiAnalyzerWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →