CVE-2018-13376
An uninitialized memory buffer leak exists in Fortinet FortiOS 5.6.1 to 5.6.3, 5.4.6 to 5.4.7, 5.2 all versions under web proxy's disclaimer response web pages, potentially causing sensitive data to be displayed in the HTTP response.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.12%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
An uninitialized memory buffer leak exists in Fortinet FortiOS 5.6.1 to 5.6.3, 5.4.6 to 5.4.7, 5.2 all versions under web proxy's disclaimer response web pages, potentially causing sensitive data to be displayed in the HTTP response.
- CVSS 3.0
- 7.5 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 2.12% probability · 81th percentile
- CISA KEV
- Not listed
- Affected
- fortinet/fortios
- Source
- psirt@fortinet.com
References
- http://www.securityfocus.com/bid/106036Third Party Advisory, VDB Entry
- https://fortiguard.com/advisory/FG-IR-18-325Vendor Advisory
- https://herolab.usd.de/wp-content/uploads/sites/4/2018/12/usd20180031.txtExploit, Third Party Advisory
- http://www.securityfocus.com/bid/106036Third Party Advisory, VDB Entry
- https://fortiguard.com/advisory/FG-IR-18-325Vendor Advisory
- https://herolab.usd.de/wp-content/uploads/sites/4/2018/12/usd20180031.txtExploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.