Lucene search

K
cveFortinetCVE-2018-1355
HistoryJun 27, 2018 - 8:29 p.m.

CVE-2018-1355

2018-06-2720:29:04
CWE-601
fortinet
web.nvd.nist.gov
24
fortimanager
fortianalyzer
open redirect
vulnerability
script code injection
pdf conversion
nvd

CVSS2

5.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:P/A:N

CVSS3

6.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

AI Score

6

Confidence

High

EPSS

0.002

Percentile

59.2%

An open redirect vulnerability in Fortinet FortiManager 6.0.0, 5.6.5 and below versions, FortiAnalyzer 6.0.0, 5.6.5 and below versions allows attacker to inject script code during converting a HTML table to a PDF document under the FortiView feature. An attacker may be able to social engineer an authenticated user into generating a PDF file containing injected malicious URLs.

Affected configurations

Nvd
Node
fortinetfortianalyzerRange5.6.5
OR
fortinetfortianalyzerMatch6.0.0
OR
fortinetfortimanagerRange5.6.5
OR
fortinetfortimanagerMatch6.0.0
VendorProductVersionCPE
fortinetfortianalyzer*cpe:2.3:a:fortinet:fortianalyzer:*:*:*:*:*:*:*:*
fortinetfortianalyzer6.0.0cpe:2.3:a:fortinet:fortianalyzer:6.0.0:*:*:*:*:*:*:*
fortinetfortimanager*cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:*
fortinetfortimanager6.0.0cpe:2.3:a:fortinet:fortimanager:6.0.0:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "Fortinet FortiManager, FortiAnalyzer",
    "vendor": "Fortinet, Inc.",
    "versions": [
      {
        "status": "affected",
        "version": "FortiManager 6.0.0, 5.6.5 and below versions"
      },
      {
        "status": "affected",
        "version": "FortiAnalyzer 6.0.0, 5.6.5 and below versions"
      }
    ]
  }
]

CVSS2

5.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:P/A:N

CVSS3

6.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

AI Score

6

Confidence

High

EPSS

0.002

Percentile

59.2%

Related for CVE-2018-1355