CVE-2017-14182Improper Input Validation in Fortinet Fortios

Severity
6.5MEDIUMNVD
EPSS
1.5%
top 19.13%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 27
Latest updateMay 17

Description

A Denial of Service (DoS) vulnerability in Fortinet FortiOS 5.4.0 to 5.4.5 allows an authenticated user to cause the web GUI to be temporarily unresponsive, via passing a specially crafted payload to the 'params' parameter of the JSON web API.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages2 packages

NVDfortinet/fortios6 versions+5
CVEListV5fortinet/fortinet_fortiosFortiOS 5.4.5, 5.4.4, 5.4.3, 5.4.2, 5.4.1, 5.4.0

🔴Vulnerability Details

2
GHSA
GHSA-663g-ww93-9qmp: A Denial of Service (DoS) vulnerability in Fortinet FortiOS 52022-05-17
CVEList
CVE-2017-14182: A Denial of Service (DoS) vulnerability in Fortinet FortiOS 52017-10-27

📋Vendor Advisories

1
Fortinet
A Denial of Service (DoS) vulnerability in Fortinet FortiOS 5.4.0 to 5.4.5 allows an authenticated user to cause the web...2017-10-27
CVE-2017-14182 — Improper Input Validation in Fortinet | cvebase