← All CVEs

CVE-2018-13383

medium · 4.3Actively exploited

On the CISA Known Exploited Vulnerabilities catalog

Apply updates per vendor instructions.

Added 2022-01-10Remediation due 2022-07-10

A heap buffer overflow in Fortinet FortiOS 6.0.0 through 6.0.4, 5.6.0 through 5.6.10, 5.4.0 through 5.4.12, 5.2.14 and earlier and FortiProxy 2.0.0, 1.2.8 and earlier in the SSL VPN web portal may cause the SSL VPN web service termination for logged in users due to a failure to properly handle javascript href data when proxying webpages.

4.3
CVSS
33.6%
EPSS (exploit prob.)
98th
EPSS percentile
2019-05-29
Published

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

Weaknesses

CWE-787

Affected products

VendorProductAffected versions
fortinetfortiproxy< 1.2.9
fortinetfortiproxy2.0.0
fortinetfortios>= 5.2.0, < 5.2.15
fortinetfortios>= 5.4.0, < 5.4.13
fortinetfortios>= 5.6.0, < 5.6.11
fortinetfortios>= 6.0.0, < 6.0.5

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2018-13383