A Denial of Service (DoS) vulnerability in Fortinet FortiOS 5.4.0 to 5.4.5 allows an authenticated user to cause the web GUI to be temporarily unresponsive, via passing a specially crafted payload to the 'params' parameter of the JSON web API.
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
http://code610.blogspot.com/2017/10/patch-your-fortinet-cve-2017-14182.html | third party advisory |
http://www.securitytracker.com/id/1039678 | vdb entry third party advisory |
https://fortiguard.com/psirt/FG-IR-17-206 | vendor advisory |
http://www.securityfocus.com/bid/101559 | vdb entry third party advisory |