Junglewise Threat Intelligence

CVE-2018-13379: Fortinet FortiOS SSL VPN Path Traversal Vulnerability

CVE-2018-13379 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2021-11-03

Technologies: Fortinet FortiOS, Fortinet FortiProxy. Vendors: Fortinet.

Executive brief

A path traversal vulnerability in the Fortinet FortiOS and FortiProxy SSL VPN web portal allows an unauthenticated remote attacker to download sensitive system files. This is achieved by sending specially crafted HTTP resource requests to the affected device.

Affected products

  • Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.3 to 5.6.7, 5.4.6 to 5.4.12
  • Fortinet FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7

Timeline

  • 2021-11-03: kev added: Added to CISA's Known Exploited Vulnerabilities Catalog
  • 2021-11-03: disclosed

Related threats