High severity8.8NVD Advisory· Published Mar 15, 2020· Updated Jun 17, 2026
CVE-2019-17654
CVE-2019-17654
Description
An Insufficient Verification of Data Authenticity vulnerability in FortiManager 6.2.1, 6.2.0, 6.0.6 and below may allow an unauthenticated attacker to perform a Cross-Site WebSocket Hijacking (CSWSH) attack.
Affected products
5cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:*+ 4 more
- cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:*range: <=6.0.6
- cpe:2.3:a:fortinet:fortimanager:6.2.0:*:*:*:*:*:*:*
- cpe:2.3:a:fortinet:fortimanager:6.2.1:*:*:*:*:*:*:*
- (no CPE)range: <=6.0.6, 6.2.0, 6.2.1
- (no CPE)range: 6.2.1
Patches
Vulnerability mechanics
References
1- fortiguard.com/psirt/FG-IR-19-191nvdVendor Advisory
News mentions
0No linked articles in our index yet.