René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

152 lines
4.6 KiB
JSON

{
"id": "CVE-2017-14182",
"sourceIdentifier": "psirt@fortinet.com",
"published": "2017-10-27T13:29:00.217",
"lastModified": "2017-10-31T21:13:21.407",
"vulnStatus": "Analyzed",
"descriptions": [
{
"lang": "en",
"value": "A Denial of Service (DoS) vulnerability in Fortinet FortiOS 5.4.0 to 5.4.5 allows an authenticated user to cause the web GUI to be temporarily unresponsive, via passing a specially crafted payload to the 'params' parameter of the JSON web API."
},
{
"lang": "es",
"value": "Una vulnerabilidad de denegaci\u00f3n de servicio (DoS) en Fortinet FortiOS desde la versi\u00f3n 5.4.0 hasta la 5.4.5 permite que un usuario autenticado haga que la interfaz gr\u00e1fica de usuario web no responda temporalmente, pasando una carga \u00fatil especialmente manipulada al par\u00e1metro \"params\" de la API web JSON."
}
],
"metrics": {
"cvssMetricV30": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "3.0",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "LOW",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"availabilityImpact": "HIGH",
"baseScore": 6.5,
"baseSeverity": "MEDIUM"
},
"exploitabilityScore": 2.8,
"impactScore": 3.6
}
],
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:S/C:N/I:N/A:P",
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "SINGLE",
"confidentialityImpact": "NONE",
"integrityImpact": "NONE",
"availabilityImpact": "PARTIAL",
"baseScore": 4.0
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 8.0,
"impactScore": 2.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-20"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:o:fortinet:fortios:5.4.0:*:*:*:*:*:*:*",
"matchCriteriaId": "1668AE14-D9A4-4B7D-BC3F-75885792875A"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:o:fortinet:fortios:5.4.1:*:*:*:*:*:*:*",
"matchCriteriaId": "9E0F3B9B-A06F-4A96-B2E7-9DC56E629182"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:o:fortinet:fortios:5.4.2:*:*:*:*:*:*:*",
"matchCriteriaId": "50F8AE97-A647-4A37-8EF2-BC0BBCC8EADD"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:o:fortinet:fortios:5.4.3:*:*:*:*:*:*:*",
"matchCriteriaId": "377A2F0B-2A58-4C2C-B546-3178B353484B"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:o:fortinet:fortios:5.4.4:*:*:*:*:*:*:*",
"matchCriteriaId": "20EBDFD4-45A0-47CC-817E-48E84F945402"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:o:fortinet:fortios:5.4.5:*:*:*:*:*:*:*",
"matchCriteriaId": "8C9CDB2B-E454-4B91-9A47-615F31F1A3D5"
}
]
}
]
}
],
"references": [
{
"url": "http://code610.blogspot.com/2017/10/patch-your-fortinet-cve-2017-14182.html",
"source": "psirt@fortinet.com",
"tags": [
"Third Party Advisory"
]
},
{
"url": "http://www.securityfocus.com/bid/101559",
"source": "psirt@fortinet.com",
"tags": [
"Third Party Advisory",
"VDB Entry"
]
},
{
"url": "http://www.securitytracker.com/id/1039678",
"source": "psirt@fortinet.com",
"tags": [
"Third Party Advisory",
"VDB Entry"
]
},
{
"url": "https://fortiguard.com/psirt/FG-IR-17-206",
"source": "psirt@fortinet.com",
"tags": [
"Vendor Advisory"
]
}
]
}