CVE-2018-13379
Fortinet FortiOS SSL VPN Path Traversal Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
8Exploited in Wild
YesDecision
Descriptions
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.3 to 5.6.7 and 5.4.6 to 5.4.12 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7 under SSL VPN web portal allows an unauthenticated attacker to download system files via special crafted HTTP resource requests.
Una limitación inadecuada de un nombre de ruta a un directorio restringido ("Path Traversal") en Fortinet FortiOS versiones 6.0.0 a 6.0.4, 5.6.3 a 5.6.7 y 5.4.6 a 5.4.12 y FortiProxy versiones 2.0.0, 1. 2.0 a 1.2.8, 1.1.0 a 1.1.6, 1.0.0 a 1.0.7 bajo el portal web SSL VPN permite a un atacante no autenticado descargar archivos del sistema a través de solicitudes de recursos HTTP especialmente diseñadas
FortiOS versions 5.6.3 through 5.6.7 and 6.0.0 through 6.0.4 suffer from a credential disclosure vulnerability.
Fortinet FortiOS SSL VPN web portal contains a path traversal vulnerability that may allow an unauthenticated attacker to download FortiOS system files through specially crafted HTTP resource requests.
CVSS Scores
SSVC
- Decision:Act
Timeline
- 2018-07-06 CVE Reserved
- 2019-06-04 CVE Published
- 2019-08-14 First Exploit
- 2021-11-03 Exploited in Wild
- 2022-05-03 KEV Due Date
- 2024-10-23 CVE Updated
- 2024-10-25 EPSS Updated
CWE
- CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CAPEC
References (10)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/47288 | 2019-08-19 | |
https://www.exploit-db.com/exploits/47287 | 2019-08-19 | |
https://github.com/milo2012/CVE-2018-13379 | 2019-08-14 | |
https://github.com/k4nfr3/CVE-2018-13379-Fortinet | 2020-11-19 | |
https://github.com/B1anda0/CVE-2018-13379 | 2020-12-14 | |
https://github.com/yukar1z0e/CVE-2018-13379 | 2020-05-21 | |
https://github.com/pwn3z/CVE-2018-13379-FortinetVPN | 2020-11-05 | |
https://github.com/nivdolgin/CVE-2018-13379 | 2021-09-11 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://fortiguard.com/advisory/FG-IR-18-384 | 2024-07-25 | |
https://www.fortiguard.com/psirt/FG-IR-20-233 | 2024-07-25 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Fortinet Search vendor "Fortinet" | Fortiproxy Search vendor "Fortinet" for product "Fortiproxy" | <= 1.2.8 Search vendor "Fortinet" for product "Fortiproxy" and version " <= 1.2.8" | - |
Affected
| ||||||
Fortinet Search vendor "Fortinet" | Fortiproxy Search vendor "Fortinet" for product "Fortiproxy" | 2.0.0 Search vendor "Fortinet" for product "Fortiproxy" and version "2.0.0" | - |
Affected
| ||||||
Fortinet Search vendor "Fortinet" | Fortios Search vendor "Fortinet" for product "Fortios" | >= 5.4.6 < 5.4.13 Search vendor "Fortinet" for product "Fortios" and version " >= 5.4.6 < 5.4.13" | - |
Affected
| ||||||
Fortinet Search vendor "Fortinet" | Fortios Search vendor "Fortinet" for product "Fortios" | >= 5.6.3 < 5.6.8 Search vendor "Fortinet" for product "Fortios" and version " >= 5.6.3 < 5.6.8" | - |
Affected
| ||||||
Fortinet Search vendor "Fortinet" | Fortios Search vendor "Fortinet" for product "Fortios" | >= 6.0.0 < 6.0.5 Search vendor "Fortinet" for product "Fortios" and version " >= 6.0.0 < 6.0.5" | - |
Affected
|