SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2018-13382

Fortinet FortiOS and FortiProxy Improper Authorization

KEVHIGH 7.5EPSS 81.7%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 10 July 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

An Improper Authorization vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8 and 5.4.1 to 5.4.10 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7 under SSL VPN web portal allows an unauthenticated attacker to modify the password of an SSL VPN web portal user via specially crafted HTTP requests

CVSS 3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
EPSS
81.69% probability · 100th percentile
CISA KEV
Listed 10 January 2022 · due 10 July 2022 · used in ransomware campaigns
Weakness
CWE-863
Affected
fortinet/fortiproxy · fortinet/fortios
Source
psirt@fortinet.com

CISA notes

Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2018-13382

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.