CVE-2018-13383
Summary
| CVE | CVE-2018-13383 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-05-29 18:29:00 UTC |
| Updated | 2021-03-16 15:48:00 UTC |
| Description | A heap buffer overflow in Fortinet FortiOS 6.0.0 through 6.0.4, 5.6.0 through 5.6.10, 5.4.0 through 5.4.12, 5.2.14 and earlier and FortiProxy 2.0.0, 1.2.8 and earlier in the SSL VPN web portal may cause the SSL VPN web service termination for logged in users due to a failure to properly handle javascript href data when proxying webpages. |
Risk And Classification
EPSS: 0.336470000 probability, percentile 0.982090000 (date 2026-07-21)
CISA KEV: Listed on 2022-01-10; due 2022-07-10; ransomware use Known
Problem Types: CWE-787
CISA Known Exploited Vulnerability
| Vendor | Fortinet |
|---|---|
| Product | FortiOS and FortiProxy |
| Name | Fortinet FortiOS and FortiProxy Out-of-bounds Write |
| Required Action | Apply updates per vendor instructions. |
| Notes | https://nvd.nist.gov/vuln/detail/CVE-2018-13383 |
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Fortinet | Fortios | All | All | All | All |
| Operating System | Fortinet | Fortios | All | All | All | All |
| Operating System | Fortinet | Fortios | All | All | All | All |
| Operating System | Fortinet | Fortios | All | All | All | All |
| Operating System | Fortinet | Fortios | All | All | All | All |
| Application | Fortinet | Fortiproxy | 2.0.0 | All | All | All |
| Application | Fortinet | Fortiproxy | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| FortiGuard | CONFIRM | fortiguard.com | Vendor Advisory |
| Fortinet | Enterprise Security Without Compromise | CONFIRM | fortiguard.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
| CISA Known Exploited Vulnerabilities catalog | CISA | www.cisa.gov | kev |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.