High severity7.5NVD Advisory· Published Apr 7, 2020· Updated Jun 17, 2026
CVE-2019-17657
CVE-2019-17657
Description
An Uncontrolled Resource Consumption vulnerability in Fortinet FortiSwitch below 3.6.11, 6.0.6 and 6.2.2, FortiAnalyzer below 6.2.3, FortiManager below 6.2.3 and FortiAP-S/W2 below 6.2.2 may allow an attacker to cause admin webUI denial of service (DoS) via handling special crafted HTTP requests/responses in pieces slowly, as demonstrated by Slow HTTP DoS Attacks.
Affected products
9cpe:2.3:a:fortinet:fortianalyzer:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:fortinet:fortianalyzer:*:*:*:*:*:*:*:*range: <6.2.3
- (no CPE)range: <6.2.3
cpe:2.3:a:fortinet:fortiap-w2:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:fortinet:fortiap-w2:*:*:*:*:*:*:*:*range: <6.2.2
- (no CPE)range: <6.2.2
cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:fortinet:fortimanager:*:*:*:*:*:*:*:*range: <6.2.3
- (no CPE)range: <6.2.3
cpe:2.3:o:fortinet:fortiswitch:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:fortinet:fortiswitch:*:*:*:*:*:*:*:*range: <3.6.11
- (no CPE)range: <3.6.11, 6.0.6 and 6.2.2
Patches
Vulnerability mechanics
References
1- fortiguard.com/psirt/FG-IR-19-013nvdVendor Advisory
News mentions
0No linked articles in our index yet.