ID

VAR-201505-0127


CVE

CVE-2014-8618


TITLE

Fortinet FortiADC D Cross-site scripting vulnerability in login page for model theme

Trust: 0.8

sources: JVNDB: JVNDB-2014-008044

DESCRIPTION

Cross-site scripting (XSS) vulnerability in the theme login page in Fortinet FortiADC D models before 4.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and launch other attacks. Versions prior to FortiADC-D 4.2 are vulnerable. Fortinet FortiADC is an application delivery controller from Fortinet, which optimizes network availability, user experience, mobile performance and cloud-based enterprise application control, and enhances server efficiency and reduces data center network complexity. sex and cost. D is one of the modules

Trust: 1.98

sources: NVD: CVE-2014-8618 // JVNDB: JVNDB-2014-008044 // BID: 74678 // VULHUB: VHN-76563

AFFECTED PRODUCTS

vendor:fortinetmodel:fortiadc-2000dscope:eqversion: -

Trust: 1.0

vendor:fortinetmodel:fortiadc-1500dscope:eqversion: -

Trust: 1.0

vendor:fortinetmodel:fortiadcscope:lteversion:4.1.0

Trust: 1.0

vendor:fortinetmodel:fortiadc-4000dscope:eqversion: -

Trust: 1.0

vendor:fortinetmodel:fortiadc-200dscope:eqversion: -

Trust: 1.0

vendor:fortinetmodel:fortiadc-700dscope:eqversion: -

Trust: 1.0

vendor:fortinetmodel:fortiadcscope:ltversion:4.2

Trust: 0.8

vendor:fortinetmodel:fortiadc-1500dscope: - version: -

Trust: 0.8

vendor:fortinetmodel:fortiadc-2000dscope: - version: -

Trust: 0.8

vendor:fortinetmodel:fortiadc-200dscope: - version: -

Trust: 0.8

vendor:fortinetmodel:fortiadc-4000dscope: - version: -

Trust: 0.8

vendor:fortinetmodel:fortiadc-700dscope: - version: -

Trust: 0.8

vendor:fortinetmodel:fortiadcscope:eqversion:4.1.0

Trust: 0.6

vendor:fortinetmodel:fortiadc-dscope:eqversion:0

Trust: 0.3

vendor:fortinetmodel:fortiadc-dscope:neversion:4.2

Trust: 0.3

sources: BID: 74678 // JVNDB: JVNDB-2014-008044 // CNNVD: CNNVD-201505-095 // NVD: CVE-2014-8618

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2014-8618
value: MEDIUM

Trust: 1.0

NVD: CVE-2014-8618
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-201505-095
value: MEDIUM

Trust: 0.6

VULHUB: VHN-76563
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2014-8618
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-76563
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-76563 // JVNDB: JVNDB-2014-008044 // CNNVD: CNNVD-201505-095 // NVD: CVE-2014-8618

PROBLEMTYPE DATA

problemtype:CWE-79

Trust: 1.9

sources: VULHUB: VHN-76563 // JVNDB: JVNDB-2014-008044 // NVD: CVE-2014-8618

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201505-095

TYPE

XSS

Trust: 0.6

sources: CNNVD: CNNVD-201505-095

CONFIGURATIONS

sources: JVNDB: JVNDB-2014-008044

PATCH

title:Multiple products cross-site scripting vulnerabilitiesurl:http://www.fortiguard.com/advisory/FG-IR-15-005/

Trust: 0.8

sources: JVNDB: JVNDB-2014-008044

EXTERNAL IDS

db:NVDid:CVE-2014-8618

Trust: 2.8

db:SECTRACKid:1032265

Trust: 1.1

db:JVNDBid:JVNDB-2014-008044

Trust: 0.8

db:CNNVDid:CNNVD-201505-095

Trust: 0.7

db:BIDid:74678

Trust: 0.4

db:VULHUBid:VHN-76563

Trust: 0.1

sources: VULHUB: VHN-76563 // BID: 74678 // JVNDB: JVNDB-2014-008044 // CNNVD: CNNVD-201505-095 // NVD: CVE-2014-8618

REFERENCES

url:http://www.fortiguard.com/advisory/fg-ir-15-005/

Trust: 2.0

url:http://www.securitytracker.com/id/1032265

Trust: 1.1

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2014-8618

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2014-8618

Trust: 0.8

url:http://www.fortinet.com/products/fortiadc/

Trust: 0.3

sources: VULHUB: VHN-76563 // BID: 74678 // JVNDB: JVNDB-2014-008044 // CNNVD: CNNVD-201505-095 // NVD: CVE-2014-8618

CREDITS

Jared Haight, William Costa and Benjamin Kunz Mejri

Trust: 0.3

sources: BID: 74678

SOURCES

db:VULHUBid:VHN-76563
db:BIDid:74678
db:JVNDBid:JVNDB-2014-008044
db:CNNVDid:CNNVD-201505-095
db:NVDid:CVE-2014-8618

LAST UPDATE DATE

2024-08-14T13:47:42.555000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-76563date:2017-01-03T00:00:00
db:BIDid:74678date:2015-02-25T00:00:00
db:JVNDBid:JVNDB-2014-008044date:2015-05-14T00:00:00
db:CNNVDid:CNNVD-201505-095date:2015-05-13T00:00:00
db:NVDid:CVE-2014-8618date:2017-01-03T02:59:20.407

SOURCES RELEASE DATE

db:VULHUBid:VHN-76563date:2015-05-12T00:00:00
db:BIDid:74678date:2015-02-25T00:00:00
db:JVNDBid:JVNDB-2014-008044date:2015-05-14T00:00:00
db:CNNVDid:CNNVD-201505-095date:2015-05-13T00:00:00
db:NVDid:CVE-2014-8618date:2015-05-12T19:59:01.377