{
    "id": "CVE-2018-13382",
    "published": "2019-06-04 21:29:00",
    "last_modified": "2026-06-17 01:39:18",
    "cvss_score": "9.1",
    "cvss_severity": "CRITICAL",
    "cvss_version": "3.1",
    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
    "cwe": "CWE-863",
    "description": "An Improper Authorization vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8 and 5.4.1 to 5.4.10 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7 under SSL VPN web portal allows an unauthenticated attacker to modify the password of an SSL VPN web portal user via specially crafted HTTP requests",
    "epss_score": "0.81691",
    "epss_percentile": "0.99635",
    "kev": 1,
    "kev_due": "2022-07-10",
    "has_exploit": 1,
    "updated_at": "2026-09-26 18:24:20",
    "priority": {
        "rank": 1,
        "label": "Patch first",
        "why": "On CISA KEV — known exploited in the wild, due 2022-07-10."
    },
    "products": [
        {
            "vendor": "fortinet",
            "product": "fortios"
        },
        {
            "vendor": "fortinet",
            "product": "fortiproxy"
        }
    ],
    "kev_detail": {
        "cve_id": "CVE-2018-13382",
        "date_added": "2022-01-10",
        "due_date": "2022-07-10",
        "vendor": "Fortinet",
        "product": "FortiOS and FortiProxy",
        "name": "Fortinet FortiOS and FortiProxy Improper Authorization",
        "ransomware": 1
    },
    "exploits": [
        {
            "source": "exploit-db",
            "ref_id": "49074",
            "title": "Fortinet FortiOS 6.0.4 - Unauthenticated SSL VPN User Password Modification",
            "date": "2020-11-19",
            "url": "https://www.exploit-db.com/exploits/49074"
        }
    ],
    "refs_list": [
        "https://fortiguard.com/advisory/FG-IR-18-389",
        "https://www.fortiguard.com/psirt/FG-IR-20-231",
        "https://fortiguard.com/advisory/FG-IR-18-389",
        "https://www.fortiguard.com/psirt/FG-IR-20-231",
        "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-13382"
    ]
}