Impact
The vulnerability is an improper neutralization of input during web page generation (Cross‑Site Scripting) found in several Fortinet devices. An authenticated remote user can craft requests that contain malicious scripts, which the firmware fails to sanitize before rendering in a browser context. Exploitation can lead to arbitrary code execution or command execution on the device, thereby compromising the confidentiality, integrity, and availability of the system.
Affected Systems
Affected products include Fortinet FortiOS (versions 7.6.0 through 7.6.6, all 7.4 releases, all 7.2 releases), FortiPAM (all versions up to 1.8.0), and FortiProxy (versions 7.4.0 through 7.4.3 and 7.2.0 through 7.2.9).
Risk and Exploitability
The CVSS score of 6.1 indicates a medium severity, while the EPSS score of less than 1% suggests a low probability of exploitation in the current environment. The vulnerability is not listed in the CISA KEV catalog. Attackers would need authenticated access to the device and would leverage crafted web requests that are not properly sanitized. Although the potential impact is high, the likelihood of a successful exploit remains low at this time.
OpenCVE Enrichment