CVE-2018-13382
Fortinet FortiOS and FortiProxy Improper Authorization
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
YesDecision
Descriptions
An Improper Authorization vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8 and 5.4.1 to 5.4.10 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7 under SSL VPN web portal allows an unauthenticated attacker to modify the password of an SSL VPN web portal user via specially crafted HTTP requests
Una vulnerabilidad de autorización inadecuada en Fortinet FortiOS versiones 6.0.0 a 6.0.4, 5.6.0 a 5.6.8 y 5.4.1 a 5.4.10 y FortiProxy versiones 2.0.0, 1.2.0 a 1.2.8, 1.1.0 a 1.1.6, 1.0.0 a 1.0.7 en el portal web SSL VPN permite a un atacante no autenticado modificar la contraseña de un usuario del portal web SSL VPN a través de peticiones HTTP especialmente diseñadas
Fortinet FortiOS version 6.0.4 suffers from an unauthenticated SSL VPN user password modification vulnerability.
An Improper Authorization vulnerability in Fortinet FortiOS and FortiProxy under SSL VPN web portal allows an unauthenticated attacker to modify the password.
CVSS Scores
SSVC
- Decision:Act
Timeline
- 2018-07-06 CVE Reserved
- 2019-06-04 CVE Published
- 2019-08-13 First Exploit
- 2022-01-10 Exploited in Wild
- 2022-07-10 KEV Due Date
- 2024-07-25 EPSS Updated
- 2024-10-23 CVE Updated
CWE
- CWE-863: Incorrect Authorization
CAPEC
References (4)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/49074 | 2020-11-19 | |
https://github.com/milo2012/CVE-2018-13382 | 2019-08-13 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://fortiguard.com/advisory/FG-IR-18-389 | 2024-07-24 | |
https://www.fortiguard.com/psirt/FG-IR-20-231 | 2024-07-24 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Fortinet Search vendor "Fortinet" | Fortiproxy Search vendor "Fortinet" for product "Fortiproxy" | < 1.2.9 Search vendor "Fortinet" for product "Fortiproxy" and version " < 1.2.9" | - |
Affected
| ||||||
Fortinet Search vendor "Fortinet" | Fortiproxy Search vendor "Fortinet" for product "Fortiproxy" | 2.0.0 Search vendor "Fortinet" for product "Fortiproxy" and version "2.0.0" | - |
Affected
| ||||||
Fortinet Search vendor "Fortinet" | Fortios Search vendor "Fortinet" for product "Fortios" | >= 5.4.1 <= 5.4.10 Search vendor "Fortinet" for product "Fortios" and version " >= 5.4.1 <= 5.4.10" | - |
Affected
| ||||||
Fortinet Search vendor "Fortinet" | Fortios Search vendor "Fortinet" for product "Fortios" | >= 5.6.0 <= 5.6.8 Search vendor "Fortinet" for product "Fortios" and version " >= 5.6.0 <= 5.6.8" | - |
Affected
| ||||||
Fortinet Search vendor "Fortinet" | Fortios Search vendor "Fortinet" for product "Fortios" | >= 6.0.0 <= 6.0.4 Search vendor "Fortinet" for product "Fortios" and version " >= 6.0.0 <= 6.0.4" | - |
Affected
|