CVE-2017-3127: XSS
Published Jun 1, 2017
·Updated
A Cross-Site Scripting vulnerability in Fortinet FortiGate 5.2.0 through 5.2.10 allows attacker to execute unauthorized code or commands via the srcintf parameter during Firewall Policy Creation.
Affected Software
11 affected components
Fortinet FortiOS=5.2.0
Fortinet FortiOS=5.2.1
Fortinet FortiOS=5.2.2
Fortinet FortiOS=5.2.3
Fortinet FortiOS=5.2.4
Fortinet FortiOS=5.2.5
Fortinet FortiOS=5.2.6
Fortinet FortiOS=5.2.7
Fortinet FortiOS=5.2.8
Fortinet FortiOS=5.2.9
Fortinet FortiOS=5.2.10
Event History
Jun 1, 2017
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-3127?
CVE-2017-3127 is considered a high severity vulnerability due to its potential for remote code execution through Cross-Site Scripting.
2
How do I fix CVE-2017-3127?
To remediate CVE-2017-3127, upgrade Fortinet FortiGate to version 5.2.11 or later as per the recommended security updates.
3
What software versions are affected by CVE-2017-3127?
CVE-2017-3127 affects Fortinet FortiGate versions 5.2.0 through 5.2.10.
4
Can CVE-2017-3127 be exploited remotely?
Yes, CVE-2017-3127 can be exploited remotely by an attacker to execute unauthorized commands.
5
What type of vulnerability is CVE-2017-3127?
CVE-2017-3127 is a Cross-Site Scripting (XSS) vulnerability allowing execution of scripts in the user's browser.