cbcvebase.
CVE-2017-14187
published 2018-05-24

CVE-2017-14187: A local privilege escalation and local code execution vulnerability in Fortinet FortiOS 5.6.0 to 5.6.2, 5.4.0 to 5.4.8, and 5.2 and below versions allows…

PriorityP423medium6.2CVSS 3.0
AVPACLPRHUINSUCHIHAH
EPSS
0.46%
36.8th percentile
A local privilege escalation and local code execution vulnerability in Fortinet FortiOS 5.6.0 to 5.6.2, 5.4.0 to 5.4.8, and 5.2 and below versions allows attacker to execute unauthorized binary program contained on an USB drive plugged into a FortiGate via linking the aforementioned binary program to a command that is allowed to be run by the fnsysctl CLI command.

Affected

9 ranges
VendorProductVersion rangeFixed in
fortinetfortigate
fortinetfortinet
fortinetfortios<= 5.2.0
fortinetfortios
fortinetfortios5.4.0 – 5.4.8
fortinetfortios5.6.0 – 5.6.2
fortinet_incfortios
fortinet_incfortios
fortinet_incfortios

CVSS provenance

nvdv3.06.2MEDIUMCVSS:3.0/AV:P/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.