CVE-2017-14185: Infoleak
An Information Disclosure vulnerability in Fortinet FortiOS 5.6.0 to 5.6.2, 5.4.0 to 5.4.8 and 5.2 all versions allows SSL VPN web portal users to access internal FortiOS configuration information (eg:addresses) via specifically crafted URLs inside the SSL-VPN web portal.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-14185?
CVE-2017-14185 has a medium severity rating due to the potential exposure of internal FortiOS configuration information.
How do I fix CVE-2017-14185?
To fix CVE-2017-14185, update FortiOS to version 5.6.3 or later, or to version 5.4.9 or later.
What systems are affected by CVE-2017-14185?
CVE-2017-14185 affects FortiOS versions from 5.2.0 to 5.2.13, 5.4.0 to 5.4.8, and 5.6.0 to 5.6.2.
What kind of information can be disclosed through CVE-2017-14185?
CVE-2017-14185 allows SSL VPN web portal users to access internal configuration information such as IP addresses.
Is CVE-2017-14185 exploitable by remote attackers?
CVE-2017-14185 can be exploited by authenticated SSL VPN web portal users, posing a risk to the organization's internal information.