CVE-2018-13379
Fortinet FortiOS SSL VPN Path Traversal Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 3 May 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.3 to 5.6.7 and 5.4.6 to 5.4.12 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7 under SSL VPN web portal allows an unauthenticated attacker to download system files via special crafted HTTP resource requests.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 100.00% probability · 100th percentile
- CISA KEV
- Listed 3 November 2021 · due 3 May 2022 · used in ransomware campaigns
- Weakness
- CWE-22
- Affected
- fortinet/fortiproxy · fortinet/fortios
- Source
- psirt@fortinet.com
CISA notes
Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2018-13379
References
- https://fortiguard.com/advisory/FG-IR-18-384Mitigation, Vendor Advisory
- https://www.fortiguard.com/psirt/FG-IR-20-233Vendor Advisory
- https://fortiguard.com/advisory/FG-IR-18-384Mitigation, Vendor Advisory
- https://www.fortiguard.com/psirt/FG-IR-20-233Vendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-13379US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.