{"api_version":"1","generated_at":"2026-07-23T09:02:10+00:00","cve":"CVE-2017-14184","urls":{"html":"https://cve.report/CVE-2017-14184","api":"https://cve.report/api/cve/CVE-2017-14184.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2017-14184","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2017-14184"},"summary":{"title":"CVE-2017-14184","description":"An Information Disclosure vulnerability in Fortinet FortiClient for Windows 5.6.0 and below versions, FortiClient for Mac OSX 5.6.0 and below versions and FortiClient SSLVPN Client for Linux 4.4.2334 and below versions allows regular users to see each other's VPN authentication credentials due to improperly secured storage locations.","state":"PUBLISHED","assigner":"fortinet","published_at":"2017-12-15 21:29:00","updated_at":"2025-04-20 01:37:25"},"problem_types":["CWE-200","Information Disclosure"],"metrics":[{"version":"3.0","source":"nvd@nist.gov","type":"Primary","score":"8.8","severity":"HIGH","vector":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","data":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4","severity":"","vector":"AV:N/AC:L/Au:S/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"https://fortiguard.com/advisory/FG-IR-17-214","name":"https://fortiguard.com/advisory/FG-IR-17-214","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mitigation","Vendor Advisory"],"title":"FortiClient insecure VPN credential storage and encryption | FortiGuard","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/102123","name":"http://www.securityfocus.com/bid/102123","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"Fortinet FortiClient CVE-2017-14184 Local Information Disclosure Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2017-14184","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2017-14184","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Fortinet, Inc.","product":"FortiClient for Windows","version":"affected 5.6.0 and below","platforms":[]},{"source":"CNA","vendor":"Fortinet, Inc.","product":"FortiClient for Mac OSX","version":"affected 5.6.0 and below","platforms":[]},{"source":"CNA","vendor":"Fortinet, Inc.","product":"FortiClient SSLVPN Client for Linux","version":"affected 4.4.2334 and below","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2017","cve_id":"14184","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"fortinet","cpe5":"forticlient","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"macos","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"14184","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"fortinet","cpe5":"forticlient","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"windows","cpe12":"*","cpe13":"*"},{"cve_year":"2017","cve_id":"14184","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"fortinet","cpe5":"forticlient_sslvpn_client","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"linux","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2017","cve_id":"14184","cve":"CVE-2017-14184","epss":"0.016490000","percentile":"0.822130000","score_date":"2026-05-18","updated_at":"2026-05-19 00:10:21"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-05T19:20:41.245Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://fortiguard.com/advisory/FG-IR-17-214"},{"name":"102123","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/102123"}],"title":"CVE Program Container"},{"metrics":[{"other":{"content":{"id":"CVE-2017-14184","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","timestamp":"2024-10-24T20:04:03.769096Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2024-10-25T14:32:46.074Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"product":"FortiClient for Windows","vendor":"Fortinet, Inc.","versions":[{"status":"affected","version":"5.6.0 and below"}]},{"product":"FortiClient for Mac OSX","vendor":"Fortinet, Inc.","versions":[{"status":"affected","version":"5.6.0 and below"}]},{"product":"FortiClient SSLVPN Client for Linux","vendor":"Fortinet, Inc.","versions":[{"status":"affected","version":"4.4.2334 and below"}]}],"datePublic":"2017-12-07T00:00:00.000Z","descriptions":[{"lang":"en","value":"An Information Disclosure vulnerability in Fortinet FortiClient for Windows 5.6.0 and below versions, FortiClient for Mac OSX 5.6.0 and below versions and FortiClient SSLVPN Client for Linux 4.4.2334 and below versions allows regular users to see each other's VPN authentication credentials due to improperly secured storage locations."}],"problemTypes":[{"descriptions":[{"description":"Information Disclosure","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-12-16T10:57:01.000Z","orgId":"6abe59d8-c742-4dff-8ce8-9b0ca1073da8","shortName":"fortinet"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"https://fortiguard.com/advisory/FG-IR-17-214"},{"name":"102123","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/102123"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"psirt@fortinet.com","DATE_PUBLIC":"2017-12-07T00:00:00","ID":"CVE-2017-14184","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"FortiClient for Windows","version":{"version_data":[{"version_value":"5.6.0 and below"}]}},{"product_name":"FortiClient for Mac OSX","version":{"version_data":[{"version_value":"5.6.0 and below"}]}},{"product_name":"FortiClient SSLVPN Client for Linux","version":{"version_data":[{"version_value":"4.4.2334 and below"}]}}]},"vendor_name":"Fortinet, Inc."}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"An Information Disclosure vulnerability in Fortinet FortiClient for Windows 5.6.0 and below versions, FortiClient for Mac OSX 5.6.0 and below versions and FortiClient SSLVPN Client for Linux 4.4.2334 and below versions allows regular users to see each other's VPN authentication credentials due to improperly secured storage locations."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Information Disclosure"}]}]},"references":{"reference_data":[{"name":"https://fortiguard.com/advisory/FG-IR-17-214","refsource":"CONFIRM","url":"https://fortiguard.com/advisory/FG-IR-17-214"},{"name":"102123","refsource":"BID","url":"http://www.securityfocus.com/bid/102123"}]}}}},"cveMetadata":{"assignerOrgId":"6abe59d8-c742-4dff-8ce8-9b0ca1073da8","assignerShortName":"fortinet","cveId":"CVE-2017-14184","datePublished":"2017-12-15T21:00:00.000Z","dateReserved":"2017-09-07T00:00:00.000Z","dateUpdated":"2024-10-25T14:32:46.074Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2017-12-15 21:29:00","lastModifiedDate":"2025-04-20 01:37:25","problem_types":["CWE-200","Information Disclosure"],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:fortinet:forticlient:*:*:*:*:*:windows:*:*","versionEndExcluding":"5.6.0","matchCriteriaId":"FF770657-32BD-4CE2-BB3E-50A9AD8BFD18"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:fortinet:forticlient:*:*:*:*:*:macos:*:*","versionEndExcluding":"5.6.0","matchCriteriaId":"AF2D5D8E-4658-486E-836F-2F7B98109F82"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:fortinet:forticlient_sslvpn_client:*:*:*:*:*:linux:*:*","versionEndExcluding":"4.4.2334","matchCriteriaId":"4D0218F0-8C34-4F8A-B435-74B1F2C484AF"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2017","CveId":"14184","Ordinal":"1","Title":"CVE-2017-14184","CVE":"CVE-2017-14184","Year":"2017"},"notes":[{"CveYear":"2017","CveId":"14184","Ordinal":"1","NoteData":"An Information Disclosure vulnerability in Fortinet FortiClient for Windows 5.6.0 and below versions, FortiClient for Mac OSX 5.6.0 and below versions and FortiClient SSLVPN Client for Linux 4.4.2334 and below versions allows regular users to see each other's VPN authentication credentials due to improperly secured storage locations.","Type":"Description","Title":"CVE-2017-14184"},{"CveYear":"2017","CveId":"14184","Ordinal":"2","NoteData":"2017-12-15","Type":"Other","Title":"Published"},{"CveYear":"2017","CveId":"14184","Ordinal":"3","NoteData":"2017-12-16","Type":"Other","Title":"Modified"}]}}}