Junglewise Threat Intelligence

CVE-2018-13383: Fortinet FortiOS and FortiProxy Out-of-bounds Write

CVE-2018-13383 · Severity: critical · CVSS 6.5 · Exploited in the wild · Published 2022-01-10

Technologies: Fortinet FortiOS, Fortinet FortiProxy. Vendors: Fortinet.

Executive brief

A heap buffer overflow vulnerability in the SSL VPN web portal of Fortinet FortiOS and FortiProxy occurs when proxying webpages due to improper handling of JavaScript href data. This flaw can allow a remote attacker to cause the termination of the SSL VPN web service for logged-in users.

Affected products

  • Fortinet FortiOS 6.0.0 through 6.0.4, 5.6.0 through 5.6.10, 5.4.0 through 5.4.12, 5.2.14 and earlier
  • Fortinet FortiProxy 2.0.0, 1.2.8 and earlier

Timeline

  • 2022-01-10: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-01-10: disclosed
  • 2022-01-10: exploited: Reported as exploited in the wild per CISA KEV and advisory metadata.

Related threats