CVE-2018-13382 KEV EXPLOIT
9.1
CRITICAL · CVSS 3.1 · EPSS 81.7% (pctl 100)
Patch first
On CISA KEV — known exploited in the wild, due 2022-07-10.
Description
An Improper Authorization vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8 and 5.4.1 to 5.4.10 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7 under SSL VPN web portal allows an unauthenticated attacker to modify the password of an SSL VPN web portal user via specially crafted HTTP requests
Scoring
| CVSS | 9.1 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
| EPSS | 81.69% — more likely to be exploited than 100% of all CVEs |
| Weakness | CWE-863 |
| On CISA KEV | yes — remediate by 2022-07-10 |
| Public exploit | yes |
| Published | 2019-06-04 |
| Last modified | 2026-06-17 |
CISA KEV
| Name | Fortinet FortiOS and FortiProxy Improper Authorization |
|---|---|
| Added | 2022-01-10 |
| Due | 2022-07-10 |
| Vendor / product | Fortinet / FortiOS and FortiProxy |
| Ransomware use | known |
Affected (2)
| Vendor | Product |
|---|---|
| fortinet | fortios |
| fortinet | fortiproxy |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Fortinet FortiOS 6.0.4 - Unauthenticated SSL VPN User Password Modification | 2020-11-19 |
References
→ the Explorer · watch your stack · NVD