Description
A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.6.0 and earlier allows attackers to execute unauthorized code or commands via the Replacement Message HTML for SSL-VPN.
In plain language
AI Worth attentionCVE-2017-3133 is a web bug in Fortinet FortiOS SSL-VPN (5.6.0 and earlier) where an attacker can inject a malicious web script into the SSL-VPN “Replacement Message” HTML; small businesses should take it seriously because it’s reachable over the network without login, but it does require a user to click/use the affected page.
In Fortinet FortiOS (5.6.0 and earlier), a cross-site scripting (CWE-79) weakness lets an attacker inject malicious script into the SSL-VPN “Replacement Message” HTML, enabling execution of unintended actions in a victim’s browser via network-triggered injection without authentication.
What to do now
- Check your Fortinet FortiOS version and confirm it is 5.6.0 or earlier, and whether SSL-VPN is enabled.
- Review your SSL-VPN “Replacement Message” content/HTML to ensure no unexpected or user-supplied data is being included.
- Update FortiOS to a later version as described in Fortinet’s advisory FG-IR-17-104 (the fixed remediation).
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:RUser InteractionS:CScopeC:LConfidentialityI:LIntegrityA:NAvailabilityWeaknesses
Affected Products
Exploitability
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2017-3133 and every CVE in our database. Create a free account — no credit card required.
Create Free Account