CVE-2017-14184

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
15/12/2017
Last modified:
20/04/2025

Description

An Information Disclosure vulnerability in Fortinet FortiClient for Windows 5.6.0 and below versions, FortiClient for Mac OSX 5.6.0 and below versions and FortiClient SSLVPN Client for Linux 4.4.2334 and below versions allows regular users to see each other's VPN authentication credentials due to improperly secured storage locations.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:fortinet:forticlient:*:*:*:*:*:windows:*:* 5.6.0 (excluding)
cpe:2.3:a:fortinet:forticlient:*:*:*:*:*:macos:*:* 5.6.0 (excluding)
cpe:2.3:a:fortinet:forticlient_sslvpn_client:*:*:*:*:*:linux:*:* 4.4.2334 (excluding)