VulnerabilityModified
CVE-2017-14191
An Improper Access Control vulnerability in Fortinet FortiWeb 5.6.0 up to but not including 6.1.0 under "Signed Security Mode", allows attacker to bypass the signed user cookie protection by removing the FortiWeb own protection session cookie.
MEDIUM 5.9EPSS 0.95%
Does this matter?
Lower severity and a low EPSS score (0.95%). Track it; it rarely justifies an emergency change on its own.
Description
An Improper Access Control vulnerability in Fortinet FortiWeb 5.6.0 up to but not including 6.1.0 under "Signed Security Mode", allows attacker to bypass the signed user cookie protection by removing the FortiWeb own protection session cookie.
- CVSS 3.0
- 5.9 MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 0.95% probability · 59th percentile
- CISA KEV
- Not listed
- Affected
- fortinet/fortiweb
- Source
- psirt@fortinet.com
References
- http://www.securityfocus.com/bid/103430Mitigation, Third Party Advisory, VDB Entry
- https://fortiguard.com/advisory/FG-IR-17-279Vendor Advisory
- http://www.securityfocus.com/bid/103430Mitigation, Third Party Advisory, VDB Entry
- https://fortiguard.com/advisory/FG-IR-17-279Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.