CVE-2018-13379 is a critical path traversal vulnerability affecting the SSL VPN web portal in various versions of Fortinet FortiOS and FortiProxy. Rated with a CVSS score of 9.8, this flaw allows unauthenticated remote attackers to download system files via specially crafted HTTP requests, leading to the exposure of sensitive session data and plaintext credentials without requiring user interaction. The vulnerability is actively exploited in the wild by ransomware cartels and APT groups, earning it a place in the CISA Known Exploited Vulnerabilities catalog. With public exploit code available in frameworks like Metasploit and confirmed reports of massive credential leaks, immediate remediation is essential to prevent unauthorized network access.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.2.9CPE matchmatch criteria | cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:* | ||
2.0.0CPE matchmatch criteria | cpe:2.3:a:fortinet:fortiproxy:2.0.0:*:*:*:*:*:*:* | ||
>= 5.4.6, < 5.4.13CPE matchmatch criteria | cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:* | ||
>= 5.6.3, < 5.6.8CPE matchmatch criteria | cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:* | ||
>= 6.0.0, < 6.0.5CPE matchmatch criteria | cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.