peter bassill · operator
$ cve CVE-2018-13383 JSON

CVE-2018-13383 KEV

4.3
MEDIUM · CVSS 3.1 · EPSS 33.6% (pctl 98)

Patch first

On CISA KEV — known exploited in the wild, due 2022-07-10.

Description

A heap buffer overflow in Fortinet FortiOS 6.0.0 through 6.0.4, 5.6.0 through 5.6.10, 5.4.0 through 5.4.12, 5.2.14 and earlier and FortiProxy 2.0.0, 1.2.8 and earlier in the SSL VPN web portal may cause the SSL VPN web service termination for logged in users due to a failure to properly handle javascript href data when proxying webpages.

Scoring

CVSS4.3 (MEDIUM, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
EPSS33.65% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-787
On CISA KEVyes — remediate by 2022-07-10
Public exploitnone known
Published2019-05-29
Last modified2026-06-17

CISA KEV

NameFortinet FortiOS and FortiProxy Out-of-bounds Write
Added2022-01-10
Due2022-07-10
Vendor / productFortinet / FortiOS and FortiProxy
Ransomware useknown

Affected (2)

VendorProduct
fortinetfortios
fortinetfortiproxy

References

→ the Explorer  ·  watch your stack  ·  NVD