CVE-2018-13382
critical · 9.1Actively exploitedOn the CISA Known Exploited Vulnerabilities catalog
Apply updates per vendor instructions.
Added 2022-01-10Remediation due 2022-07-10
An Improper Authorization vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8 and 5.4.1 to 5.4.10 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7 under SSL VPN web portal allows an unauthenticated attacker to modify the password of an SSL VPN web portal user via specially crafted HTTP requests
9.1
CVSS
81.7%
EPSS (exploit prob.)
100th
EPSS percentile
2019-06-04
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Weaknesses
CWE-863
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| fortinet | fortiproxy | < 1.2.9 |
| fortinet | fortiproxy | 2.0.0 |
| fortinet | fortios | >= 5.4.1, < 5.4.11 |
| fortinet | fortios | >= 5.6.0, < 5.6.9 |
| fortinet | fortios | >= 6.0.0, < 6.0.5 |
Check a specific version with /api/v1/cve/match.
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2018-13382