CVE-2017-14182

MEDIUM

FortiOS 5.4.0-5.4.5 - Authenticated Denial of Service via JSON API Params Parameter

Title source: llm
STIX 2.1

Description

A Denial of Service (DoS) vulnerability in Fortinet FortiOS 5.4.0 to 5.4.5 allows an authenticated user to cause the web GUI to be temporarily unresponsive, via passing a specially crafted payload to the 'params' parameter of the JSON web API.

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1039678
Vendor Advisory x_refsource_confirm
https://fortiguard.com/psirt/FG-IR-17-206
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/101559

Scores

CVSS v3 6.5
EPSS 0.0146
EPSS Percentile 81.1%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-20
Status published
Products (7)
Fortinet/Fortinet FortiOS FortiOS 5.4.5, 5.4.4, 5.4.3, 5.4.2, 5.4.1, 5.4.0
fortinet/fortios 5.4.0
fortinet/fortios 5.4.1
fortinet/fortios 5.4.2
fortinet/fortios 5.4.3
fortinet/fortios 5.4.4
fortinet/fortios 5.4.5
Published Oct 27, 2017
Tracked Since Feb 18, 2026