CVE-2017-17541: XSS
A Cross-site Scripting (XSS) vulnerability in Fortinet FortiManager 6.0.0, 5.6.4 and below versions, FortiAnalyzer 6.0.0, 5.6.4 and below versions allows inject Javascript code and HTML tags through the CN value of CA and CRL certificates via the import CA and CRL certificates feature.
Affected Software
Event History
Frequently Asked Questions
What are the affected versions of Fortinet FortiManager and FortiAnalyzer for CVE-2017-17541?
CVE-2017-17541 affects Fortinet FortiManager versions 6.0.0, 5.6.4 and below, and Fortinet FortiAnalyzer versions 6.0.0, 5.6.4 and below.
What type of vulnerability is CVE-2017-17541?
CVE-2017-17541 is a Cross-site Scripting (XSS) vulnerability.
How can attackers exploit CVE-2017-17541?
Attackers can exploit CVE-2017-17541 by injecting JavaScript code and HTML tags through the CN value of CA and CRL certificates when importing them.
What impact does CVE-2017-17541 have on affected systems?
CVE-2017-17541 allows attackers to execute malicious scripts in the context of users accessing the affected applications.
How do I remediate CVE-2017-17541?
To remediate CVE-2017-17541, upgrade to the latest unaffected versions of FortiManager and FortiAnalyzer.