CVE-2018-13383
Fortinet FortiOS and FortiProxy Out-of-bounds Write
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 10 July 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
A heap buffer overflow in Fortinet FortiOS 6.0.0 through 6.0.4, 5.6.0 through 5.6.10, 5.4.0 through 5.4.12, 5.2.14 and earlier and FortiProxy 2.0.0, 1.2.8 and earlier in the SSL VPN web portal may cause the SSL VPN web service termination for logged in users due to a failure to properly handle javascript href data when proxying webpages.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
- EPSS
- 33.65% probability · 98th percentile
- CISA KEV
- Listed 10 January 2022 · due 10 July 2022 · used in ransomware campaigns
- Weakness
- CWE-787
- Affected
- fortinet/fortiproxy · fortinet/fortios
- Source
- psirt@fortinet.com
CISA notes
Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2018-13383
References
- https://fortiguard.com/advisory/FG-IR-18-388Mitigation, Vendor Advisory
- https://fortiguard.com/advisory/FG-IR-20-229Vendor Advisory
- https://fortiguard.com/advisory/FG-IR-18-388Mitigation, Vendor Advisory
- https://fortiguard.com/advisory/FG-IR-20-229Vendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-13383US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.