CVE-2017-14182
published 2017-10-27CVE-2017-14182: A Denial of Service (DoS) vulnerability in Fortinet FortiOS 5.4.0 to 5.4.5 allows an authenticated user to cause the web GUI to be temporarily unresponsive…
PriorityP428medium6.5CVSS 3.0
AVNACLPRLUINSUCNINAH
EPSS
1.75%
75.3th percentile
A Denial of Service (DoS) vulnerability in Fortinet FortiOS 5.4.0 to 5.4.5 allows an authenticated user to cause the web GUI to be temporarily unresponsive, via passing a specially crafted payload to the 'params' parameter of the JSON web API.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortinet | — | — |
| fortinet | fortinet_fortios | — | — |
| fortinet | fortios | — | — |
| fortinet | fortios | — | — |
| fortinet | fortios | — | — |
| fortinet | fortios | — | — |
| fortinet | fortios | — | — |
| fortinet | fortios | — | — |
| fortinet | fortios | — | — |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:N/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-663g-ww93-9qmp: A Denial of Service (DoS) vulnerability in Fortinet FortiOS 5
ghsa_unreviewed·2022-05-17
CVE-2017-14182 [MEDIUM] CWE-20 GHSA-663g-ww93-9qmp: A Denial of Service (DoS) vulnerability in Fortinet FortiOS 5
A Denial of Service (DoS) vulnerability in Fortinet FortiOS 5.4.0 to 5.4.5 allows an authenticated user to cause the web GUI to be temporarily unresponsive, via passing a specially crafted payload to the 'params' parameter of the JSON web API.
Fortinet
A Denial of Service (DoS) vulnerability in Fortinet FortiOS 5.4.0 to 5.4.5 allows an authenticated user to cause the web...
vendor_fortinet·2017-10-27·CVSS 6.5
CVE-2017-14182 [MEDIUM] CWE-20 A Denial of Service (DoS) vulnerability in Fortinet FortiOS 5.4.0 to 5.4.5 allows an authenticated user to cause the web...
FG-IR-17-206: A Denial of Service (DoS) vulnerability in Fortinet FortiOS 5.4.0 to 5.4.5 allows an authenticated user to cause the web...
A Denial of Service (DoS) vulnerability in Fortinet FortiOS 5.4.0 to 5.4.5 allows an authenticated user to cause the web GUI to be temporarily unresponsive, via passing a specially crafted payload to the 'params' parameter of the JSON web API.
CVEs: CVE-2017-14182
CWEs: CWE-20
CVSS: 6.5 (medium)
Affected products: FortiOS, Fortinet
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://code610.blogspot.com/2017/10/patch-your-fortinet-cve-2017-14182.htmlhttp://www.securityfocus.com/bid/101559http://www.securitytracker.com/id/1039678https://fortiguard.com/psirt/FG-IR-17-206http://code610.blogspot.com/2017/10/patch-your-fortinet-cve-2017-14182.htmlhttp://www.securityfocus.com/bid/101559http://www.securitytracker.com/id/1039678https://fortiguard.com/psirt/FG-IR-17-206
2017-10-27
Published