CVE-2017-14185
Last modified
CVE-2017-14185 is a vulnerability of currently unknown severity. An Information Disclosure vulnerability in Fortinet FortiOS 5.6.0 to 5.6.2, 5.4.0 to 5.4.8 and 5.2 all versions allows SSL VPN web portal users to access internal FortiOS configuration information (eg:addresses) via specifically crafted URLs inside the SSL-VPN web portal.. EPSS estimates a 1.34% chance of exploitation in the next 30 days.
Description
An Information Disclosure vulnerability in Fortinet FortiOS 5.6.0 to 5.6.2, 5.4.0 to 5.4.8 and 5.2 all versions allows SSL VPN web portal users to access internal FortiOS configuration information (eg:addresses) via specifically crafted URLs inside the SSL-VPN web portal.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Fortinet | Fortios | >= 5.2.0, <= 5.2.13 |
| Fortinet | Fortios | >= 5.4.0, <= 5.4.8 |
| Fortinet | Fortios | >= 5.6.0, <= 5.6.2 |
References
- http://www.securityfocus.com/bid/104288Third Party Advisory, VDB Entry
- https://fortiguard.com/advisory/FG-IR-17-231Vendor Advisory
- http://www.securityfocus.com/bid/104288Third Party Advisory, VDB Entry
- https://fortiguard.com/advisory/FG-IR-17-231Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-14185?
How severe is CVE-2017-14185?
How do I fix CVE-2017-14185?
Are you affected by CVE-2017-14185?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
