CVE-2017-14185Sensitive Information Exposure in Fortinet Fortios

Severity
5.3MEDIUMNVD
EPSS
0.3%
top 44.27%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 25
Latest updateMay 14

Description

An Information Disclosure vulnerability in Fortinet FortiOS 5.6.0 to 5.6.2, 5.4.0 to 5.4.8 and 5.2 all versions allows SSL VPN web portal users to access internal FortiOS configuration information (eg:addresses) via specifically crafted URLs inside the SSL-VPN web portal.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages2 packages

NVDfortinet/fortios5.2.05.2.13+2
CVEListV5fortinet_inc/fortios5.2 all versions, 5.4.0 to 5.4.8, 5.6.0 to 5.6.2+2

🔴Vulnerability Details

2
GHSA
GHSA-x7pw-4585-684g: An Information Disclosure vulnerability in Fortinet FortiOS 52022-05-14
CVEList
CVE-2017-14185: An Information Disclosure vulnerability in Fortinet FortiOS 52018-05-25

📋Vendor Advisories

1
Fortinet
An Information Disclosure vulnerability in Fortinet FortiOS 5.6.0 to 5.6.2, 5.4.0 to 5.4.8 and 5.2 all versions allows S...2018-05-25
CVE-2017-14185 — Sensitive Information Exposure | cvebase