CVE-2017-14186
Summary
| CVE | CVE-2017-14186 |
|---|---|
| State | PUBLISHED |
| Assigner | fortinet |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-11-29 19:29:00 UTC |
| Updated | 2025-04-20 01:37:25 UTC |
| Description | A Cross-site Scripting (XSS) vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.7, 5.4 and below versions under SSL VPN web portal allows a remote user to inject arbitrary web script or HTML in the context of the victim's browser via the login redir parameter. An URL Redirection attack may also be feasible by injecting an external URL via the affected parameter. |
Risk And Classification
Primary CVSS: v3.0 5.4 MEDIUM from [email protected]
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
EPSS: 0.029810000 probability, percentile 0.866620000 (date 2026-05-14)
Problem Types: CWE-79 | Cross-site Scripting (XSS), URL Redirection Attack
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.0 | [email protected] | Primary | 5.4 | MEDIUM | CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
| 2.0 | [email protected] | Primary | 3.5 | AV:N/AC:M/Au:S/C:N/I:P/A:N |
CVSS v3.0 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
LowUser Interaction
RequiredScope
ChangedConfidentiality
LowIntegrity
LowAvailability
NoneCVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
SingleConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:M/Au:S/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Fortinet Inc. | FortiOS | affected 5.6.0 to 5.6.2 | Not specified |
| CNA | Fortinet Inc. | FortiOS | affected 5.4.0 to 5.4.6 | Not specified |
| CNA | Fortinet Inc. | FortiOS | affected 5.2.0 to 5.2.12 | Not specified |
| CNA | Fortinet Inc. | FortiOS | affected 5.0 and below | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Fortinet FortiGate/FortiOS SSL-VPN Input Validation Flaw in login redir Parameter Lets Remote Users Conduct Cross-Site Scripting and Open Redirect Attacks - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | Third Party Advisory, VDB Entry |
| Fortinet FortiOS CVE-2017-14186 URI Redirection and Cross Site Scripting Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Third Party Advisory, VDB Entry |
| FortiGate SSL VPN web portal login redir XSS vulnerability | FortiGuard | af854a3a-2127-422b-91ae-364da2661108 | fortiguard.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.