VYPR
High severity7.5NVD Advisory· Published Apr 7, 2020· Updated Jun 17, 2026

CVE-2019-17657

CVE-2019-17657

Description

An Uncontrolled Resource Consumption vulnerability in Fortinet FortiSwitch below 3.6.11, 6.0.6 and 6.2.2, FortiAnalyzer below 6.2.3, FortiManager below 6.2.3 and FortiAP-S/W2 below 6.2.2 may allow an attacker to cause admin webUI denial of service (DoS) via handling special crafted HTTP requests/responses in pieces slowly, as demonstrated by Slow HTTP DoS Attacks.

Affected products

9
  • cpe:2.3:a:fortinet:fortianalyzer:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:fortinet:fortianalyzer:*:*:*:*:*:*:*:*range: <6.2.3
    • (no CPE)range: <6.2.3
  • cpe:2.3:a:fortinet:fortiap-s:*:*:*:*:*:*:*:*
    Range: <6.2.2
  • cpe:2.3:a:fortinet:fortiap-w2:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:fortinet:fortiap-w2:*:*:*:*:*:*:*:*range: <6.2.2
    • (no CPE)range: <6.2.2
  • cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:*range: <6.2.3
    • (no CPE)range: <6.2.3
  • cpe:2.3:o:fortinet:fortiswitch:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:fortinet:fortiswitch:*:*:*:*:*:*:*:*range: <3.6.11
    • (no CPE)range: <3.6.11, 6.0.6 and 6.2.2

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.