An Information Disclosure vulnerability in Fortinet FortiOS 5.6.0 to 5.6.2, 5.4.0 to 5.4.8 and 5.2 all versions allows SSL VPN web portal users to access internal FortiOS configuration information (eg:addresses) via specifically crafted URLs inside the SSL-VPN web portal.
History

Fri, 25 Oct 2024 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: fortinet

Published: 2018-05-25T16:00:00Z

Updated: 2024-10-25T14:31:46.387Z

Reserved: 2017-09-07T00:00:00

Link: CVE-2017-14185

cve-icon Vulnrichment

Updated: 2024-08-05T19:20:41.083Z

cve-icon NVD

Status : Analyzed

Published: 2018-05-25T16:29:00.230

Modified: 2018-06-27T11:12:55.200

Link: CVE-2017-14185

cve-icon Redhat

No data.