SSL-VPN Reflected XSS
A reflected cross-site scripting (XSS) vulnerability exists in the SSL-VPN portal of Fortinet FortiOS, FortiPAM, and FortiProxy. An attacker can inject malicious JavaScript into the portal by crafting a special URL. When a user clicks the malicious link, the JavaScript runs in their browser, potentially allowing the attacker to steal credentials or session tokens. The vulnerability affects FortiOS 7.6.0–7.6.6, all 7.4 and 7.2 versions; FortiPAM 1.8.0, all 1.7 and 1.6 versions; and FortiProxy 7.4.0–7.4.3 and 7.2.0–7.2.9. Patches are available for several product lines, though older branches require migration to newer versions.
- User must click on attacker-crafted link
- SSL-VPN portal must be reachable from the internet
- Vulnerable Fortinet product (FortiOS, FortiPAM, or FortiProxy) must be running an affected version
Patching may require device reboot — plan for process interruption
/api/v1/advisories/47214021-212f-4184-9d0d-c73651ec35deGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.