CVE-2019-17657
published 2020-04-07CVE-2019-17657: An Uncontrolled Resource Consumption vulnerability in Fortinet FortiSwitch below 3.6.11, 6.0.6 and 6.2.2, FortiAnalyzer below 6.2.3, FortiManager below 6.2.3…
PriorityP339high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
2.38%
82.0th percentile
An Uncontrolled Resource Consumption vulnerability in Fortinet FortiSwitch below 3.6.11, 6.0.6 and 6.2.2, FortiAnalyzer below 6.2.3, FortiManager below 6.2.3 and FortiAP-S/W2 below 6.2.2 may allow an attacker to cause admin webUI denial of service (DoS) via handling special crafted HTTP requests/responses in pieces slowly, as demonstrated by Slow HTTP DoS Attacks.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortiap-s | w2 | — | — |
| fortinet | fortianalyzer | < 6.2.3 | 6.2.3 |
| fortinet | fortianalyzer | — | — |
| fortinet | fortianalyzer | — | — |
| fortinet | fortiap | — | — |
| fortinet | fortiap-s | < 6.2.2 | 6.2.2 |
| fortinet | fortiap-s | — | — |
| fortinet | fortiap-w2 | < 6.2.2 | 6.2.2 |
| fortinet | fortiap-w2 | — | — |
| fortinet | fortimanager | < 6.2.3 | 6.2.3 |
| fortinet | fortimanager | — | — |
| fortinet | fortimanager | — | — |
| fortinet | fortinet | — | — |
| fortinet | fortiswitch | < 3.6.11 | 3.6.11 |
| fortinet | fortiswitch | — | — |
| fortinet | fortiswitch | >= 6.0.0 < 6.0.6 | 6.0.6 |
| fortinet | fortiswitch | >= 6.2.0 < 6.2.2 | 6.2.2 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Fortinet
An Uncontrolled Resource Consumption vulnerability in Fortinet FortiSwitch below 3.6.11, 6.0.6 and 6.2.2, FortiAnalyzer...
vendor_fortinet·2020-04-07·CVSS 7.5
CVE-2019-17657 [HIGH] CWE-400 An Uncontrolled Resource Consumption vulnerability in Fortinet FortiSwitch below 3.6.11, 6.0.6 and 6.2.2, FortiAnalyzer...
FG-IR-19-013: An Uncontrolled Resource Consumption vulnerability in Fortinet FortiSwitch below 3.6.11, 6.0.6 and 6.2.2, FortiAnalyzer...
An Uncontrolled Resource Consumption vulnerability in Fortinet FortiSwitch below 3.6.11, 6.0.6 and 6.2.2, FortiAnalyzer below 6.2.3, FortiManager below 6.2.3 and FortiAP-S/W2 below 6.2.2 may allow an attacker to cause admin webUI denial of service (DoS) via handling special crafted HTTP requests/responses in pieces slowly, as demonstrated by Slow HTTP DoS Attacks.
CVEs: CVE-2019-17657
CWEs: CWE-400
CVSS: 7.5 (high)
Affected products: FortiAP, FortiAnalyzer, FortiAp-s, FortiAp-w2, FortiManager, FortiSwitch, Fortinet
GHSA
GHSA-j8g4-vw7x-cwpr: An Uncontrolled Resource Consumption vulnerability in Fortinet FortiSwitch below 3
ghsa_unreviewed·2022-05-24
CVE-2019-17657 [MEDIUM] GHSA-j8g4-vw7x-cwpr: An Uncontrolled Resource Consumption vulnerability in Fortinet FortiSwitch below 3
An Uncontrolled Resource Consumption vulnerability in Fortinet FortiSwitch below 3.6.11, 6.0.6 and 6.2.2, FortiAnalyzer below 6.2.3, FortiManager below 6.2.3 and FortiAP-S/W2 below 6.2.2 may allow an attacker to cause admin webUI denial of service (DoS) via handling special crafted HTTP requests/responses in pieces slowly, as demonstrated by Slow HTTP DoS Attacks.
OSV
CVE-2019-17657: An Uncontrolled Resource Consumption vulnerability in Fortinet FortiSwitch below 3
osv·2020-04-07·CVSS 7.5
CVE-2019-17657 [HIGH] CVE-2019-17657: An Uncontrolled Resource Consumption vulnerability in Fortinet FortiSwitch below 3
An Uncontrolled Resource Consumption vulnerability in Fortinet FortiSwitch below 3.6.11, 6.0.6 and 6.2.2, FortiAnalyzer below 6.2.3, FortiManager below 6.2.3 and FortiAP-S/W2 below 6.2.2 may allow an attacker to cause admin webUI denial of service (DoS) via handling special crafted HTTP requests/responses in pieces slowly, as demonstrated by Slow HTTP DoS Attacks.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-04-07
Published