CVE-2017-14189
critical
CVSS v3
9.8
CVSS v2
10.0
VIR risk
9.8
Description
An improper access control vulnerability in Fortinet FortiWebManager 5.8.0 allows anyone that can access the admin webUI to successfully log-in regardless the provided password.
Predictions
Exploit likelihood
97%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: psirt@fortinet.com — https://fortiguard.com/advisory/FG-IR-17-248
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| fortinet | fortiweb_manager | 5.8.0 | |
References
CWEs
CWE-521
Verify integrity in audit chain (admin only). AS-IS.