CVE-2017-14187
published 2018-05-24CVE-2017-14187: A local privilege escalation and local code execution vulnerability in Fortinet FortiOS 5.6.0 to 5.6.2, 5.4.0 to 5.4.8, and 5.2 and below versions allows…
PriorityP423medium6.2CVSS 3.0
AVPACLPRHUINSUCHIHAH
EPSS
0.46%
36.8th percentile
A local privilege escalation and local code execution vulnerability in Fortinet FortiOS 5.6.0 to 5.6.2, 5.4.0 to 5.4.8, and 5.2 and below versions allows attacker to execute unauthorized binary program contained on an USB drive plugged into a FortiGate via linking the aforementioned binary program to a command that is allowed to be run by the fnsysctl CLI command.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortigate | — | — |
| fortinet | fortinet | — | — |
| fortinet | fortios | <= 5.2.0 | — |
| fortinet | fortios | — | — |
| fortinet | fortios | 5.4.0 – 5.4.8 | — |
| fortinet | fortios | 5.6.0 – 5.6.2 | — |
| fortinet_inc | fortios | — | — |
| fortinet_inc | fortios | — | — |
| fortinet_inc | fortios | — | — |
CVSS provenance
nvdv3.06.2MEDIUMCVSS:3.0/AV:P/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-vhrf-7c9m-v558: A local privilege escalation and local code execution vulnerability in Fortinet FortiOS 5
ghsa_unreviewed·2022-05-13
CVE-2017-14187 [HIGH] CWE-269 GHSA-vhrf-7c9m-v558: A local privilege escalation and local code execution vulnerability in Fortinet FortiOS 5
A local privilege escalation and local code execution vulnerability in Fortinet FortiOS 5.6.0 to 5.6.2, 5.4.0 to 5.4.8, and 5.2 and below versions allows attacker to execute unauthorized binary program contained on an USB drive plugged into a FortiGate via linking the aforementioned binary program to a command that is allowed to be run by the fnsysctl CLI command.
Fortinet
A local privilege escalation and local code execution vulnerability in Fortinet FortiOS 5.6.0 to 5.6.2, 5.4.0 to 5.4.8,...
vendor_fortinet·2018-05-24·CVSS 6.2
CVE-2017-14187 [MEDIUM] CWE-269 A local privilege escalation and local code execution vulnerability in Fortinet FortiOS 5.6.0 to 5.6.2, 5.4.0 to 5.4.8,...
FG-IR-17-245: A local privilege escalation and local code execution vulnerability in Fortinet FortiOS 5.6.0 to 5.6.2, 5.4.0 to 5.4.8,...
A local privilege escalation and local code execution vulnerability in Fortinet FortiOS 5.6.0 to 5.6.2, 5.4.0 to 5.4.8, and 5.2 and below versions allows attacker to execute unauthorized binary program contained on an USB drive plugged into a FortiGate via linking the aforementioned binary program to a command that is allowed to be run by the fnsysctl CLI command.
CVEs: CVE-2017-14187
CWEs: CWE-269
CVSS: 6.2 (medium)
Affected products: FortiGate, FortiOS, Fortinet
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2018-05-24
Published