CVE-2017-14191
published 2018-03-20CVE-2017-14191: An Improper Access Control vulnerability in Fortinet FortiWeb 5.6.0 up to but not including 6.1.0 under "Signed Security Mode", allows attacker to bypass the…
PriorityP428medium5.9CVSS 3.0
AVNACHPRNUINSUCNIHAN
EPSS
1.01%
59.0th percentile
An Improper Access Control vulnerability in Fortinet FortiWeb 5.6.0 up to but not including 6.1.0 under "Signed Security Mode", allows attacker to bypass the signed user cookie protection by removing the FortiWeb own protection session cookie.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortinet | — | — |
| fortinet | fortiweb | — | — |
| fortinet | fortiweb | >= 5.6.0 < 6.1.0 | 6.1.0 |
| fortinet_inc | fortiweb | — | — |
CVSS provenance
nvdv3.05.9MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Fortinet
An Improper Access Control vulnerability in Fortinet FortiWeb 5.6.0 up to but not including 6.1.0 under "Signed Security...
vendor_fortinet·2018-03-20·CVSS 5.9
CVE-2017-14191 [MEDIUM] An Improper Access Control vulnerability in Fortinet FortiWeb 5.6.0 up to but not including 6.1.0 under "Signed Security...
FG-IR-17-279: An Improper Access Control vulnerability in Fortinet FortiWeb 5.6.0 up to but not including 6.1.0 under "Signed Security...
An Improper Access Control vulnerability in Fortinet FortiWeb 5.6.0 up to but not including 6.1.0 under "Signed Security Mode", allows attacker to bypass the signed user cookie protection by removing the FortiWeb own protection session cookie.
CVEs: CVE-2017-14191
CVSS: 5.9 (medium)
Affected products: FortiWeb, Fortinet
GHSA
GHSA-5xg4-jxh8-j4g8: An Improper Access Control vulnerability in Fortinet FortiWeb 5
ghsa_unreviewed·2022-05-13
CVE-2017-14191 [MEDIUM] GHSA-5xg4-jxh8-j4g8: An Improper Access Control vulnerability in Fortinet FortiWeb 5
An Improper Access Control vulnerability in Fortinet FortiWeb 5.6.0 up to but not including 6.1.0 under "Signed Security Mode", allows attacker to bypass the signed user cookie protection by removing the FortiWeb own protection session cookie.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2018-03-20
Published