First published: Thu Apr 10 2014(Updated: )
Cross-site scripting (XSS) vulnerability in the web administration interface in FortiADC with firmware before 3.2.1 allows remote attackers to inject arbitrary web script or HTML via the locale parameter to gui_partA/.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
Fortinet Fortiadc Firmware | <=3.2.0 | |
Fortinet FortiADC-1000E | ||
Fortinet FortiADC-1500D | ||
Fortinet FortiADC 2000D | ||
Fortinet FortiADC 200D | ||
Fortinet FortiADC 300E | ||
Fortinet Fortiadc-4000d | ||
Fortinet FortiADC 400E | ||
Fortinet FortiADC-600E |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-0331 is classified as a medium severity vulnerability due to its potential for exploitation through cross-site scripting.
To fix CVE-2014-0331, upgrade FortiADC firmware to version 3.2.1 or later.
CVE-2014-0331 is a cross-site scripting (XSS) vulnerability that allows attackers to inject scripts via the locale parameter.
FortiADC firmware versions prior to 3.2.1 are affected by CVE-2014-0331.
Yes, CVE-2014-0331 can be exploited remotely by attackers through the web administration interface.