Junglewise Threat Intelligence

CVE-2018-13382: Fortinet FortiOS and FortiProxy Improper Authorization

CVE-2018-13382 · Severity: critical · CVSS 9.1 · Exploited in the wild · Published 2022-01-10

Technologies: Fortinet FortiOS, Fortinet FortiProxy. Vendors: Fortinet.

Executive brief

An improper authorization vulnerability in the SSL VPN web portal of Fortinet FortiOS and FortiProxy allows an unauthenticated remote attacker to modify the password of a portal user. This is achieved by sending specially crafted HTTP requests to the affected system.

Affected products

  • Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8, 5.4.1 to 5.4.10
  • Fortinet FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7

Timeline

  • 2022-01-10: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-01-10: disclosed

Related threats