VYPR
Medium severity5.3NVD Advisory· Published Mar 17, 2025· Updated Jun 17, 2026

CVE-2019-6697

CVE-2019-6697

Description

An Improper Neutralization of Input vulnerability affecting FortiGate version 6.2.0 through 6.2.1, 6.0.0 through 6.0.6 in the hostname parameter of a DHCP packet under DHCP monitor page may allow an unauthenticated attacker in the same network as the FortiGate to perform a Stored Cross Site Scripting attack (XSS) by sending a crafted DHCP packet.

Affected products

3
  • Fortinet/Fortios2 versions
    cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*range: >=6.0.0,<6.0.7
    • cpe:2.3:o:fortinet:fortios:6.2.1:*:*:*:*:*:*:*range: 6.2.0
  • Range: 6.2.0-6.2.1, 6.0.0-6.0.6

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.