CVE-2018-13382: critical vulnerability in Fortinet FortiOS, FortiProxy
Published · Updated
Prioritize patching. It under exploitation confirmed by CISA and has a public proof of concept.
Apply updates per vendor instructions.
An unauthenticated attacker can change SSL VPN user passwords without logging in, by sending specially crafted requests to the web portal. This is critical because it allows unauthorized access to the VPN system.
An improper authorization flaw in the SSL VPN web portal password reset function fails to properly validate user identity, allowing unauthenticated HTTP requests to modify arbitrary user passwords. The vulnerability affects multiple Fortinet products across specific version ranges and requires no prior authentication or user interaction.
The full analysis of this CVE is available in Portuguese →
In the same product, most dangerous first.