CVE-2018-13382
Fortinet FortiOS and FortiProxy Improper Authorization
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 10 July 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
An Improper Authorization vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8 and 5.4.1 to 5.4.10 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7 under SSL VPN web portal allows an unauthenticated attacker to modify the password of an SSL VPN web portal user via specially crafted HTTP requests
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 81.69% probability · 100th percentile
- CISA KEV
- Listed 10 January 2022 · due 10 July 2022 · used in ransomware campaigns
- Weakness
- CWE-863
- Affected
- fortinet/fortiproxy · fortinet/fortios
- Source
- psirt@fortinet.com
CISA notes
Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2018-13382
References
- https://fortiguard.com/advisory/FG-IR-18-389Vendor Advisory
- https://www.fortiguard.com/psirt/FG-IR-20-231Vendor Advisory
- https://fortiguard.com/advisory/FG-IR-18-389Vendor Advisory
- https://www.fortiguard.com/psirt/FG-IR-20-231Vendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-13382US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.