CVE-2018-13383 KEV
4.3
MEDIUM · CVSS 3.1 · EPSS 33.6% (pctl 98)
Patch first
On CISA KEV — known exploited in the wild, due 2022-07-10.
Description
A heap buffer overflow in Fortinet FortiOS 6.0.0 through 6.0.4, 5.6.0 through 5.6.10, 5.4.0 through 5.4.12, 5.2.14 and earlier and FortiProxy 2.0.0, 1.2.8 and earlier in the SSL VPN web portal may cause the SSL VPN web service termination for logged in users due to a failure to properly handle javascript href data when proxying webpages.
Scoring
| CVSS | 4.3 (MEDIUM, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L |
| EPSS | 33.65% — more likely to be exploited than 98% of all CVEs |
| Weakness | CWE-787 |
| On CISA KEV | yes — remediate by 2022-07-10 |
| Public exploit | none known |
| Published | 2019-05-29 |
| Last modified | 2026-06-17 |
CISA KEV
| Name | Fortinet FortiOS and FortiProxy Out-of-bounds Write |
|---|---|
| Added | 2022-01-10 |
| Due | 2022-07-10 |
| Vendor / product | Fortinet / FortiOS and FortiProxy |
| Ransomware use | known |
Affected (2)
| Vendor | Product |
|---|---|
| fortinet | fortios |
| fortinet | fortiproxy |
References
→ the Explorer · watch your stack · NVD