{
    "id": "CVE-2018-13379",
    "published": "2019-06-04 21:29:00",
    "last_modified": "2026-06-17 01:39:18",
    "cvss_score": "9.1",
    "cvss_severity": "CRITICAL",
    "cvss_version": "3.1",
    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H",
    "cwe": "CWE-22",
    "description": "An Improper Limitation of a Pathname to a Restricted Directory (\"Path Traversal\") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.3 to 5.6.7 and 5.4.6 to 5.4.12 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7 under SSL VPN web portal allows an unauthenticated attacker to download system files via special crafted HTTP resource requests.",
    "epss_score": "0.99999",
    "epss_percentile": "0.99994",
    "kev": 1,
    "kev_due": "2022-05-03",
    "has_exploit": 1,
    "updated_at": "2026-09-26 18:24:20",
    "priority": {
        "rank": 1,
        "label": "Patch first",
        "why": "On CISA KEV — known exploited in the wild, due 2022-05-03."
    },
    "products": [
        {
            "vendor": "fortinet",
            "product": "fortios"
        },
        {
            "vendor": "fortinet",
            "product": "fortiproxy"
        }
    ],
    "kev_detail": {
        "cve_id": "CVE-2018-13379",
        "date_added": "2021-11-03",
        "due_date": "2022-05-03",
        "vendor": "Fortinet",
        "product": "FortiOS",
        "name": "Fortinet FortiOS SSL VPN Path Traversal Vulnerability",
        "ransomware": 1
    },
    "exploits": [
        {
            "source": "exploit-db",
            "ref_id": "47287",
            "title": "Fortinet FortiOS 5.6.3 - 5.6.7 / FortiOS 6.0.0 - 6.0.4 - Credentials Disclosure (Metasploit)",
            "date": "2019-08-19",
            "url": "https://www.exploit-db.com/exploits/47287"
        },
        {
            "source": "exploit-db",
            "ref_id": "47288",
            "title": "Fortinet FortiOS 5.6.3 - 5.6.7 / FortiOS 6.0.0 - 6.0.4 - Credentials Disclosure",
            "date": "2019-08-19",
            "url": "https://www.exploit-db.com/exploits/47288"
        }
    ],
    "refs_list": [
        "https://fortiguard.com/advisory/FG-IR-18-384",
        "https://www.fortiguard.com/psirt/FG-IR-20-233",
        "https://fortiguard.com/advisory/FG-IR-18-384",
        "https://www.fortiguard.com/psirt/FG-IR-20-233",
        "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-13379"
    ]
}