CVE-2017-17541: Fortinet Fortianalyzer Firmware
Medium severity, CVSS 6.1. EPSS: 0.9% chance of exploitation in the next 30 days.
A Cross-site Scripting (XSS) vulnerability in Fortinet FortiManager 6.0.0, 5.6.4 and below versions, FortiAnalyzer 6.0.0, 5.6.4 and below versions allows inject Javascript code and HTML tags through the CN value of CA and CRL certificates via the import CA and CRL certificates feature.
Affected products
- Fortinet Fortianalyzer Firmware: up to and including 5.6.4; version 6.0.0 only
- Fortinet FortiManager Firmware: up to and including 5.6.4; version 6.0.0 only
Published 2018-07-16. Last modified 2026-06-17.