cbcvebase.
CVE-2019-17657
published 2020-04-07

CVE-2019-17657: An Uncontrolled Resource Consumption vulnerability in Fortinet FortiSwitch below 3.6.11, 6.0.6 and 6.2.2, FortiAnalyzer below 6.2.3, FortiManager below 6.2.3…

high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
An Uncontrolled Resource Consumption vulnerability in Fortinet FortiSwitch below 3.6.11, 6.0.6 and 6.2.2, FortiAnalyzer below 6.2.3, FortiManager below 6.2.3 and FortiAP-S/W2 below 6.2.2 may allow an attacker to cause admin webUI denial of service (DoS) via handling special crafted HTTP requests/responses in pieces slowly, as demonstrated by Slow HTTP DoS Attacks.

Affected

17 ranges
VendorProductVersion rangeFixed in
fortiap-sw2
fortinetfortianalyzer< 6.2.36.2.3
fortinetfortianalyzer
fortinetfortianalyzer
fortinetfortiap
fortinetfortiap-s< 6.2.26.2.2
fortinetfortiap-s
fortinetfortiap-w2< 6.2.26.2.2
fortinetfortiap-w2
fortinetfortimanager< 6.2.36.2.3
fortinetfortimanager
fortinetfortimanager
fortinetfortinet
fortinetfortiswitch< 3.6.113.6.11
fortinetfortiswitch
fortinetfortiswitch>= 6.0.0 < 6.0.66.0.6
fortinetfortiswitch>= 6.2.0 < 6.2.26.2.2

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH