CVE-2017-7734: XSS
Published Sep 12, 2017
·Updated
A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.4.0 through 5.4.4 allows attackers to execute unauthorized code or commands via 'Comments' while saving Config Revisions.
Affected Software
5 affected components
Fortinet FortiOS=5.4.0
Fortinet FortiOS=5.4.1
Fortinet FortiOS=5.4.2
Fortinet FortiOS=5.4.3
Fortinet FortiOS=5.4.4
Event History
Sep 12, 2017
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-7734?
CVE-2017-7734 is classified as a high severity vulnerability due to its potential for executing unauthorized code.
2
How do I fix CVE-2017-7734?
To fix CVE-2017-7734, upgrade Fortinet FortiOS to version 5.4.5 or later.
3
What versions of Fortinet FortiOS are affected by CVE-2017-7734?
CVE-2017-7734 affects Fortinet FortiOS versions 5.4.0 through 5.4.4.
4
What type of vulnerability is CVE-2017-7734?
CVE-2017-7734 is a Cross-Site Scripting (XSS) vulnerability.
5
Can CVE-2017-7734 be exploited remotely?
Yes, CVE-2017-7734 can be exploited remotely by an attacker through the Comments feature in Config Revisions.