CVE-2018-13379
Summary
| CVE | CVE-2018-13379 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-06-04 21:29:00 UTC |
| Updated | 2021-06-03 11:15:00 UTC |
| Description | An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.3 to 5.6.7 and 5.4.6 to 5.4.12 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7 under SSL VPN web portal allows an unauthenticated attacker to download system files via special crafted HTTP resource requests. |
Risk And Classification
EPSS: 0.999990000 probability, percentile 0.999940000 (date 2026-07-21)
CISA KEV: Listed on 2021-11-03; due 2022-05-03; ransomware use Known
Problem Types: CWE-22
CISA Known Exploited Vulnerability
| Vendor | Fortinet |
|---|---|
| Product | FortiOS |
| Name | Fortinet FortiOS SSL VPN Path Traversal Vulnerability |
| Required Action | Apply updates per vendor instructions. |
| Notes | https://nvd.nist.gov/vuln/detail/CVE-2018-13379 |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| FortiOS 5.6.7 / 6.0.4 Credential Disclosure ≈ Packet Storm | MISC | packetstormsecurity.com | Third Party Advisory, VDB Entry |
| Attacking SSL VPN - Part 2: Breaking the Fortigate SSL VPN | DEVCORE | MISC | devco.re | Exploit, Third Party Advisory |
| i.blackhat.com/USA-19/Wednesday/us-19-Tsai-Infiltrating-Corporate-Intranet-L... | MISC | i.blackhat.com | Third Party Advisory |
| FortiProxy - system file leak through SSL VPN special crafted HTTP resource requests | FortiGuard | CONFIRM | www.fortiguard.com | |
| Development/CVE-2018-13379 - Summary & Emergency Mitigations.pdf at master · blacklotuslabs/Development · GitHub | MISC | github.com | |
| Fortinet FortiOS CVE-2018-13379 Directory Traversal Vulnerability | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| FortiOS system file leak through SSL VPN via specially crafted HTTP resource requests | FortiGuard | CONFIRM | fortiguard.com | Mitigation, Vendor Advisory |
| FortiOS 5.6.7 / 6.0.4 Credential Disclosure ≈ Packet Storm | MISC | packetstormsecurity.com | Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
| CISA Known Exploited Vulnerabilities catalog | CISA | www.cisa.gov | kev |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.