CVE-2017-14190: Fortinet FortiOS

Medium severity, CVSS 6.1. EPSS: 1.1% chance of exploitation in the next 30 days.

A Cross-site Scripting vulnerability in Fortinet FortiOS 5.6.0 to 5.6.2, 5.4.0 to 5.4.7, 5.2 and earlier, allows attacker to inject arbitrary web script or HTML via maliciously crafted "Host" header in user HTTP requests.

Affected products

  • Fortinet FortiOS: up to and including 5.2.0; from 5.4.0, up to and including 5.4.7; from 5.6.0, up to and including 5.6.2

Published 2018-01-29. Last modified 2026-06-17.