{"api_version":"1","generated_at":"2026-07-24T18:46:06+00:00","cve":"CVE-2018-13379","urls":{"html":"https://cve.report/CVE-2018-13379","api":"https://cve.report/api/cve/CVE-2018-13379.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2018-13379","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2018-13379"},"summary":{"title":"CVE-2018-13379","description":"An Improper Limitation of a Pathname to a Restricted Directory (\"Path Traversal\") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.3 to 5.6.7 and 5.4.6 to 5.4.12 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7 under SSL VPN web portal allows an unauthenticated attacker to download system files via special crafted HTTP resource requests.","state":"PUBLIC","assigner":"psirt@fortinet.com","published_at":"2019-06-04 21:29:00","updated_at":"2021-06-03 11:15:00"},"problem_types":["CWE-22"],"metrics":[],"references":[{"url":"http://packetstormsecurity.com/files/154146/FortiOS-5.6.7-6.0.4-Credential-Disclosure.html","name":"http://packetstormsecurity.com/files/154146/FortiOS-5.6.7-6.0.4-Credential-Disclosure.html","refsource":"MISC","tags":["Third Party Advisory","VDB Entry"],"title":"FortiOS 5.6.7 / 6.0.4 Credential Disclosure ≈ Packet Storm","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://devco.re/blog/2019/08/09/attacking-ssl-vpn-part-2-breaking-the-Fortigate-ssl-vpn/","name":"https://devco.re/blog/2019/08/09/attacking-ssl-vpn-part-2-breaking-the-Fortigate-ssl-vpn/","refsource":"MISC","tags":["Exploit","Third Party Advisory"],"title":"Attacking SSL VPN - Part 2: Breaking the Fortigate SSL VPN | DEVCORE","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://i.blackhat.com/USA-19/Wednesday/us-19-Tsai-Infiltrating-Corporate-Intranet-Like-NSA.pdf","name":"https://i.blackhat.com/USA-19/Wednesday/us-19-Tsai-Infiltrating-Corporate-Intranet-Like-NSA.pdf","refsource":"MISC","tags":["Third Party Advisory"],"title":"","mime":"application/pdf","httpstatus":"200","archivestatus":"200"},{"url":"https://www.fortiguard.com/psirt/FG-IR-20-233","name":"https://www.fortiguard.com/psirt/FG-IR-20-233","refsource":"CONFIRM","tags":[],"title":"FortiProxy - system file leak through SSL VPN special crafted HTTP resource requests | FortiGuard","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/blacklotuslabs/Development/blob/master/Mitigations/CVE/CVE-2018-13379/CVE-2018-13379%20-%20Summary%20%26%20Emergency%20Mitigations.pdf","name":"https://github.com/blacklotuslabs/Development/blob/master/Mitigations/CVE/CVE-2018-13379/CVE-2018-13379%20-%20Summary%20%26%20Emergency%20Mitigations.pdf","refsource":"MISC","tags":[],"title":"Development/CVE-2018-13379 - Summary & Emergency Mitigations.pdf at master · blacklotuslabs/Development · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/108693","name":"108693","refsource":"BID","tags":["Third Party Advisory","VDB Entry"],"title":"Fortinet FortiOS CVE-2018-13379 Directory Traversal Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://fortiguard.com/advisory/FG-IR-18-384","name":"https://fortiguard.com/advisory/FG-IR-18-384","refsource":"CONFIRM","tags":["Mitigation","Vendor Advisory"],"title":"FortiOS system file leak through SSL VPN via specially crafted HTTP resource requests | FortiGuard","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://packetstormsecurity.com/files/154147/FortiOS-5.6.7-6.0.4-Credential-Disclosure.html","name":"http://packetstormsecurity.com/files/154147/FortiOS-5.6.7-6.0.4-Credential-Disclosure.html","refsource":"MISC","tags":["Third Party Advisory","VDB Entry"],"title":"FortiOS 5.6.7 / 6.0.4 Credential Disclosure ≈ Packet Storm","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2018-13379","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2018-13379","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2018","cve_id":"13379","vulnerable":"1","versionEndIncluding":"5.6.7","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"fortinet","cpe5":"fortios","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"13379","vulnerable":"1","versionEndIncluding":"6.0.4","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"fortinet","cpe5":"fortios","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":{"cve_year":"2018","cve_id":"13379","cve":"CVE-2018-13379","vendorProject":"Fortinet","product":"FortiOS","vulnerabilityName":"Fortinet FortiOS SSL VPN Path Traversal Vulnerability","dateAdded":"2021-11-03","shortDescription":"Fortinet FortiOS SSL VPN web portal contains a path traversal vulnerability that may allow an unauthenticated attacker to download FortiOS system files through specially crafted HTTP resource requests.","requiredAction":"Apply updates per vendor instructions.","dueDate":"2022-05-03","knownRansomwareCampaignUse":"Known","notes":"https://nvd.nist.gov/vuln/detail/CVE-2018-13379","cwes":"CWE-22","catalogVersion":"2026.07.24","updated_at":"2026-07-24 18:00:38"},"epss":{"cve_year":"2018","cve_id":"13379","cve":"CVE-2018-13379","epss":"0.999990000","percentile":"0.999940000","score_date":"2026-07-23","updated_at":"2026-07-24 00:10:13"},"legacy_qids":[]},"source_records":{"cve_program":{"data_type":"CVE","data_format":"MITRE","data_version":"4.0","CVE_data_meta":{"ID":"CVE-2018-13379","ASSIGNER":"psirt@fortinet.com","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"vendor_name":"Fortinet","product":{"product_data":[{"product_name":"Fortinet FortiOS, FortiProxy","version":{"version_data":[{"version_value":"FortiOS 6.0.0 to 6.0.4, 5.6.3 to 5.6.7 and 5.4.6 to 5.4.12, FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7"}]}}]}}]}},"impact":{"cvss":{"attackComplexity":"Low","attackVector":"Network","availabilityImpact":"High","baseScore":8.9,"baseSeverity":"High","confidentialityImpact":"High","integrityImpact":"None","privilegesRequired":"None","scope":"Unchanged","userInteraction":"None","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","version":"3.1"}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Information disclosure"}]}]},"references":{"reference_data":[{"refsource":"CONFIRM","name":"https://fortiguard.com/advisory/FG-IR-18-384","url":"https://fortiguard.com/advisory/FG-IR-18-384"},{"refsource":"CONFIRM","name":"https://www.fortiguard.com/psirt/FG-IR-20-233","url":"https://www.fortiguard.com/psirt/FG-IR-20-233"}]},"description":{"description_data":[{"lang":"eng","value":"An Improper Limitation of a Pathname to a Restricted Directory (\"Path Traversal\") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.3 to 5.6.7 and 5.4.6 to 5.4.12 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7 under SSL VPN web portal allows an unauthenticated attacker to download system files via special crafted HTTP resource requests."}]}},"nvd":{"publishedDate":"2019-06-04 21:29:00","lastModifiedDate":"2021-06-03 11:15:00","problem_types":["CWE-22"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"},"exploitabilityScore":3.9,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5},"severity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*","versionStartIncluding":"5.6.3","versionEndIncluding":"5.6.7","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*","versionStartIncluding":"6.0.0","versionEndIncluding":"6.0.4","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2018","CveId":"13379","Ordinal":"130028","Title":"CVE-2018-13379","CVE":"CVE-2018-13379","Year":"2018"},"notes":[{"CveYear":"2018","CveId":"13379","Ordinal":"1","NoteData":"An Improper Limitation of a Pathname to a Restricted Directory (\"Path Traversal\") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.3 to 5.6.7 and 5.4.6 to 5.4.12 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7 under SSL VPN web portal allows an unauthenticated attacker to download system files via special crafted HTTP resource requests.","Type":"Description","Title":null},{"CveYear":"2018","CveId":"13379","Ordinal":"2","NoteData":"2019-06-04","Type":"Other","Title":"Published"},{"CveYear":"2018","CveId":"13379","Ordinal":"3","NoteData":"2021-06-03","Type":"Other","Title":"Modified"}]}}}