CVE-2017-14182: Input Validation
Published Oct 27, 2017
·Updated
A Denial of Service (DoS) vulnerability in Fortinet FortiOS 5.4.0 to 5.4.5 allows an authenticated user to cause the web GUI to be temporarily unresponsive, via passing a specially crafted payload to the 'params' parameter of the JSON web API.
Affected Software
6 affected components
Fortinet FortiOS=5.4.0
Fortinet FortiOS=5.4.1
Fortinet FortiOS=5.4.2
Fortinet FortiOS=5.4.3
Fortinet FortiOS=5.4.4
Fortinet FortiOS=5.4.5
Event History
Oct 27, 2017
CVE Published
via MITRE·01:00 PM
Data Sourced
via MITRE·01:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-14182?
CVE-2017-14182 is classified as a Denial of Service (DoS) vulnerability.
2
How does CVE-2017-14182 affect Fortinet FortiOS?
CVE-2017-14182 allows an authenticated user to make the web GUI temporarily unresponsive through a specially crafted payload.
3
Which versions of Fortinet FortiOS are affected by CVE-2017-14182?
Fortinet FortiOS versions 5.4.0 through 5.4.5 are impacted by CVE-2017-14182.
4
Can CVE-2017-14182 be exploited remotely?
CVE-2017-14182 requires authentication, so exploitation is not possible without valid user credentials.
5
What measures can be taken to mitigate CVE-2017-14182?
To mitigate CVE-2017-14182, it is recommended to upgrade Fortinet FortiOS to a version that is not vulnerable.