CVE-2017-14191
Last modified
CVE-2017-14191 is a vulnerability of currently unknown severity. An Improper Access Control vulnerability in Fortinet FortiWeb 5.6.0 up to but not including 6.1.0 under "Signed Security Mode", allows attacker to bypass the signed user cookie protection by removing the FortiWeb own protection session cookie.. EPSS estimates a 1.01% chance of exploitation in the next 30 days.
Description
An Improper Access Control vulnerability in Fortinet FortiWeb 5.6.0 up to but not including 6.1.0 under "Signed Security Mode", allows attacker to bypass the signed user cookie protection by removing the FortiWeb own protection session cookie.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Fortinet | Fortiweb | >= 5.6.0, < 6.1.0 |
References
- http://www.securityfocus.com/bid/103430Mitigation, Third Party Advisory, VDB Entry
- https://fortiguard.com/advisory/FG-IR-17-279Vendor Advisory
- http://www.securityfocus.com/bid/103430Mitigation, Third Party Advisory, VDB Entry
- https://fortiguard.com/advisory/FG-IR-17-279Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-14191?
How severe is CVE-2017-14191?
How do I fix CVE-2017-14191?
Are you affected by CVE-2017-14191?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
