VYPR
Medium severity5.9NVD Advisory· Published Mar 20, 2018· Updated Jun 17, 2026

CVE-2017-14191

CVE-2017-14191

Description

An Improper Access Control vulnerability in Fortinet FortiWeb 5.6.0 up to but not including 6.1.0 under "Signed Security Mode", allows attacker to bypass the signed user cookie protection by removing the FortiWeb own protection session cookie.

Affected products

2
  • Fortinet/Fortiwebllm-fuzzy2 versions
    <6.1.0+ 1 more
    • (no CPE)range: <6.1.0
    • (no CPE)range: 5.6.0 and above

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.