CVE-2018-13383
medium · 4.3Actively exploitedOn the CISA Known Exploited Vulnerabilities catalog
Apply updates per vendor instructions.
Added 2022-01-10Remediation due 2022-07-10
A heap buffer overflow in Fortinet FortiOS 6.0.0 through 6.0.4, 5.6.0 through 5.6.10, 5.4.0 through 5.4.12, 5.2.14 and earlier and FortiProxy 2.0.0, 1.2.8 and earlier in the SSL VPN web portal may cause the SSL VPN web service termination for logged in users due to a failure to properly handle javascript href data when proxying webpages.
4.3
CVSS
33.6%
EPSS (exploit prob.)
98th
EPSS percentile
2019-05-29
Published
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Weaknesses
CWE-787
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| fortinet | fortiproxy | < 1.2.9 |
| fortinet | fortiproxy | 2.0.0 |
| fortinet | fortios | >= 5.2.0, < 5.2.15 |
| fortinet | fortios | >= 5.4.0, < 5.4.13 |
| fortinet | fortios | >= 5.6.0, < 5.6.11 |
| fortinet | fortios | >= 6.0.0, < 6.0.5 |
Check a specific version with /api/v1/cve/match.
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2018-13383