CVE-2017-14185

MEDIUM

FortiOS 5.2.0-5.2.12, 5.4.0-5.4.8, 5.6.0-5.6.2 - Information Disclosure via SSL-VPN Web Portal

Title source: llm
STIX 2.1

Description

An Information Disclosure vulnerability in Fortinet FortiOS 5.6.0 to 5.6.2, 5.4.0 to 5.4.8 and 5.2 all versions allows SSL VPN web portal users to access internal FortiOS configuration information (eg:addresses) via specifically crafted URLs inside the SSL-VPN web portal.

References (2)

Core 2
Core References
Vendor Advisory x_refsource_confirm
https://fortiguard.com/advisory/FG-IR-17-231
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/104288

Scores

CVSS v3 5.3
EPSS 0.0033
EPSS Percentile 55.7%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-200
Status published
Products (1)
fortinet/fortios 5.2.0 - 5.2.13
Published May 25, 2018
Tracked Since Feb 18, 2026