← All CVEs

CVE-2018-13382

critical · 9.1Actively exploited

On the CISA Known Exploited Vulnerabilities catalog

Apply updates per vendor instructions.

Added 2022-01-10Remediation due 2022-07-10

An Improper Authorization vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8 and 5.4.1 to 5.4.10 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7 under SSL VPN web portal allows an unauthenticated attacker to modify the password of an SSL VPN web portal user via specially crafted HTTP requests

9.1
CVSS
81.7%
EPSS (exploit prob.)
100th
EPSS percentile
2019-06-04
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Weaknesses

CWE-863

Affected products

VendorProductAffected versions
fortinetfortiproxy< 1.2.9
fortinetfortiproxy2.0.0
fortinetfortios>= 5.4.1, < 5.4.11
fortinetfortios>= 5.6.0, < 5.6.9
fortinetfortios>= 6.0.0, < 6.0.5

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2018-13382