Fortinet FortiAnalyzer是美国飞塔(Fortinet)公司的一套集中式网络安全报告解决方案。该产品主要用于收集网络日志数据,并通过报告套件对日志中的安全事件、网络流量、Web内容等进行分析、报告、归档操作。 Fortinet FortiAnalyzer 6.4.3及以下版本, 6.2.7及以下版本和 6.0.10及以下版本存在跨站脚本漏洞,攻击者可利用该漏洞通过FortiAnalyzer中Logview的列设置执行存储的跨站点脚本攻击(XSS)。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Fortinet | Fortinet FortiAnalyzer | FortiAnalyzer 6.4.3, 6.4.2, 6.4.1, 6.4.0, 6.2.7, 6.2.6, 6.2.5, 6.2.4, 6.2.3, 6.2.2, 6.2.1, 6.2.0, 6.0.10, 6.0.9, 6.0.8, 6.0.7, 6.0.6, 6.0.5, 6.0.4, 6.0.3, 6.0.2, 6.0.1, 6.0.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2021-24019 | 8.1 HIGH | Fortinet FortiClientEms 代码问题漏洞 |
| CVE-2020-15941 | 5.4 MEDIUM | Fortinet FortiClientEms 路径遍历漏洞 |
| CVE-2021-36178 | 4.3 MEDIUM | Fortinet FortiSDNConnector 安全漏洞 |
| CVE-2021-36175 | 4.1 MEDIUM | Fortinet FortiWebManager 跨站脚本漏洞 |
| CVE-2021-36170 | 3.2 LOW | Fortinet FortiManager VM和FortiAnalyzerVm 信息泄露漏洞 |
No comments yet