CVE-2018-13382criticalunder attackransomwareCWE-863

CVE-2018-13382: critical vulnerability in Fortinet FortiOS, FortiProxy

Published · Updated

100Vexday Risk Score

Prioritize patching. It under exploitation confirmed by CISA and has a public proof of concept.

ssvc Actcvss 9.1epss 82%
from disclosure to weapon68 days
Published on NVDJun 4
1st PoC+68d
CISA KEV+951d
exploitation probability
82%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
7 public exploit(s)
Action required by CISAfederal deadline: 2022-07-10

Apply updates per vendor instructions.

In short

An unauthenticated attacker can change SSL VPN user passwords without logging in, by sending specially crafted requests to the web portal. This is critical because it allows unauthorized access to the VPN system.

Technical detail

An improper authorization flaw in the SSL VPN web portal password reset function fails to properly validate user identity, allowing unauthenticated HTTP requests to modify arbitrary user passwords. The vulnerability affects multiple Fortinet products across specific version ranges and requires no prior authentication or user interaction.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

An Improper Authorization vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8 and 5.4.1 to 5.4.10 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7 under SSL VPN web portal allows an unauthenticated attacker to modify the password of an SSL VPN web portal user via specially crafted HTTP requests
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.