ID

VAR-201706-0294


CVE

CVE-2017-3127


TITLE

Fortinet FortiGate Vulnerable to cross-site scripting

Trust: 0.8

sources: JVNDB: JVNDB-2017-004384

DESCRIPTION

A Cross-Site Scripting vulnerability in Fortinet FortiGate 5.2.0 through 5.2.10 allows attacker to execute unauthorized code or commands via the srcintf parameter during Firewall Policy Creation. Fortinet FortiOS is prone to a cross-site scripting vulnerability because it fails to properly sanitize user-supplied input. An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and launch other attacks. Fortinet FortiOS 5.2.0 through 5.2.10 are vulnerable. Fortinet FortiGate is a network security platform developed by Fortinet. The platform provides functions such as firewall, antivirus and intrusion prevention (IPS), application control, antispam, wireless controller and WAN acceleration

Trust: 1.98

sources: NVD: CVE-2017-3127 // JVNDB: JVNDB-2017-004384 // BID: 98048 // VULHUB: VHN-111330

AFFECTED PRODUCTS

vendor:fortinetmodel:fortiosscope:eqversion:5.2.6

Trust: 1.9

vendor:fortinetmodel:fortiosscope:eqversion:5.2.5

Trust: 1.9

vendor:fortinetmodel:fortiosscope:eqversion:5.2.4

Trust: 1.9

vendor:fortinetmodel:fortiosscope:eqversion:5.2.3

Trust: 1.9

vendor:fortinetmodel:fortiosscope:eqversion:5.2.2

Trust: 1.9

vendor:fortinetmodel:fortiosscope:eqversion:5.2.1

Trust: 1.9

vendor:fortinetmodel:fortiosscope:eqversion:5.2.10

Trust: 1.9

vendor:fortinetmodel:fortiosscope:eqversion:5.2.0

Trust: 1.9

vendor:fortinetmodel:fortiosscope:eqversion:5.2.7

Trust: 1.6

vendor:fortinetmodel:fortiosscope:eqversion:5.2.8

Trust: 1.6

vendor:fortinetmodel:fortiosscope:eqversion:5.2.9

Trust: 1.3

vendor:fortinetmodel:fortigatescope:eqversion:5.2.0 to 5.2.10

Trust: 0.8

vendor:fortinetmodel:fortiosscope:neversion:5.2.11

Trust: 0.3

sources: BID: 98048 // JVNDB: JVNDB-2017-004384 // CNNVD: CNNVD-201704-1510 // NVD: CVE-2017-3127

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2017-3127
value: MEDIUM

Trust: 1.0

NVD: CVE-2017-3127
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-201704-1510
value: MEDIUM

Trust: 0.6

VULHUB: VHN-111330
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2017-3127
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-111330
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2017-3127
baseSeverity: MEDIUM
baseScore: 6.1
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: REQUIRED
scope: CHANGED
confidentialityImpact: LOW
integrityImpact: LOW
availabilityImpact: NONE
exploitabilityScore: 2.8
impactScore: 2.7
version: 3.0

Trust: 1.8

sources: VULHUB: VHN-111330 // JVNDB: JVNDB-2017-004384 // CNNVD: CNNVD-201704-1510 // NVD: CVE-2017-3127

PROBLEMTYPE DATA

problemtype:CWE-79

Trust: 1.9

sources: VULHUB: VHN-111330 // JVNDB: JVNDB-2017-004384 // NVD: CVE-2017-3127

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201704-1510

TYPE

XSS

Trust: 0.6

sources: CNNVD: CNNVD-201704-1510

CONFIGURATIONS

sources: JVNDB: JVNDB-2017-004384

PATCH

title:FG-IR-17-017url:https://fortiguard.com/psirt/FG-IR-17-017

Trust: 0.8

title:Fortinet FortiOS Fixes for cross-site scripting vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=69703

Trust: 0.6

sources: JVNDB: JVNDB-2017-004384 // CNNVD: CNNVD-201704-1510

EXTERNAL IDS

db:NVDid:CVE-2017-3127

Trust: 2.8

db:BIDid:98048

Trust: 2.0

db:SECTRACKid:1038367

Trust: 1.1

db:JVNDBid:JVNDB-2017-004384

Trust: 0.8

db:CNNVDid:CNNVD-201704-1510

Trust: 0.7

db:VULHUBid:VHN-111330

Trust: 0.1

sources: VULHUB: VHN-111330 // BID: 98048 // JVNDB: JVNDB-2017-004384 // CNNVD: CNNVD-201704-1510 // NVD: CVE-2017-3127

REFERENCES

url:https://fortiguard.com/psirt/fg-ir-17-017

Trust: 2.0

url:http://www.securityfocus.com/bid/98048

Trust: 1.7

url:http://www.securitytracker.com/id/1038367

Trust: 1.1

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2017-3127

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2017-3127

Trust: 0.8

url:http://www.fortinet.com/technology/network-os-fortios.html

Trust: 0.3

sources: VULHUB: VHN-111330 // BID: 98048 // JVNDB: JVNDB-2017-004384 // CNNVD: CNNVD-201704-1510 // NVD: CVE-2017-3127

CREDITS

Amir Morshedizadeh

Trust: 0.9

sources: BID: 98048 // CNNVD: CNNVD-201704-1510

SOURCES

db:VULHUBid:VHN-111330
db:BIDid:98048
db:JVNDBid:JVNDB-2017-004384
db:CNNVDid:CNNVD-201704-1510
db:NVDid:CVE-2017-3127

LAST UPDATE DATE

2024-08-14T15:34:38.112000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-111330date:2017-07-11T00:00:00
db:BIDid:98048date:2017-05-02T00:11:00
db:JVNDBid:JVNDB-2017-004384date:2017-06-23T00:00:00
db:CNNVDid:CNNVD-201704-1510date:2017-06-02T00:00:00
db:NVDid:CVE-2017-3127date:2017-07-11T01:33:36.003

SOURCES RELEASE DATE

db:VULHUBid:VHN-111330date:2017-06-01T00:00:00
db:BIDid:98048date:2017-04-19T00:00:00
db:JVNDBid:JVNDB-2017-004384date:2017-06-23T00:00:00
db:CNNVDid:CNNVD-201704-1510date:2017-04-28T00:00:00
db:NVDid:CVE-2017-3127date:2017-06-01T14:29:00.187