CVE-2018-13379 KEV EXPLOIT
9.1
CRITICAL · CVSS 3.1 · EPSS 100% (pctl 100)
Patch first
On CISA KEV — known exploited in the wild, due 2022-05-03.
Description
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.3 to 5.6.7 and 5.4.6 to 5.4.12 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7 under SSL VPN web portal allows an unauthenticated attacker to download system files via special crafted HTTP resource requests.
Scoring
| CVSS | 9.1 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H |
| EPSS | 100% — more likely to be exploited than 100% of all CVEs |
| Weakness | CWE-22 |
| On CISA KEV | yes — remediate by 2022-05-03 |
| Public exploit | yes |
| Published | 2019-06-04 |
| Last modified | 2026-06-17 |
CISA KEV
| Name | Fortinet FortiOS SSL VPN Path Traversal Vulnerability |
|---|---|
| Added | 2021-11-03 |
| Due | 2022-05-03 |
| Vendor / product | Fortinet / FortiOS |
| Ransomware use | known |
Affected (2)
| Vendor | Product |
|---|---|
| fortinet | fortios |
| fortinet | fortiproxy |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Fortinet FortiOS 5.6.3 - 5.6.7 / FortiOS 6.0.0 - 6.0.4 - Credentials Disclosure (Metasploit) | 2019-08-19 |
| exploit-db | Fortinet FortiOS 5.6.3 - 5.6.7 / FortiOS 6.0.0 - 6.0.4 - Credentials Disclosure | 2019-08-19 |
References
→ the Explorer · watch your stack · NVD