CVE-2018-13382 is an Improper Authorization vulnerability in Fortinet FortiOS and FortiProxy SSL VPN web portals. It allows an unauthenticated attacker to modify a user's password through specially crafted HTTP requests. This vulnerability has a high CVSS score of 7.5 due to its network attack vector, low attack complexity, and high impact on integrity, requiring no user interaction. It is actively exploited, listed in CISA's KEV catalog, and has publicly available exploit code, including an ExploitDB entry, along with significant community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.2.9CPE matchmatch criteria | cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:* | ||
2.0.0CPE matchmatch criteria | cpe:2.3:a:fortinet:fortiproxy:2.0.0:*:*:*:*:*:*:* | ||
>= 5.4.1, < 5.4.11CPE matchmatch criteria | cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:* | ||
>= 5.6.0, < 5.6.9CPE matchmatch criteria | cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:* | ||
>= 6.0.0, < 6.0.5CPE matchmatch criteria | cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.