CVE-2019-17654: Fortinet FortiManager
High severity, CVSS 8.8. EPSS: 0.5% chance of exploitation in the next 30 days.
An Insufficient Verification of Data Authenticity vulnerability in FortiManager 6.2.1, 6.2.0, 6.0.6 and below may allow an unauthenticated attacker to perform a Cross-Site WebSocket Hijacking (CSWSH) attack.
Affected products
- Fortinet FortiManager: up to and including 6.0.6; version 6.2.0 only; version 6.2.1 only
Published 2020-03-15. Last modified 2026-06-17.