CVE Details

CVE-2018-13379 Fortinet FortiOS SSL VPN Path Traversal Vulnerability
Published: 2021-11-03 CVSS: 9.1 CRITICAL Product: Fortinet FortiOS Due Date: 2022-05-03

Fortinet FortiOS SSL VPN web portal contains a path traversal vulnerability that may allow an unauthenticated attacker to download FortiOS system files through specially crafted HTTP resource requests.

GitHub PoC

Warning: GitHub PoC repositories are unverified. Some may be fake or contain malware. Use caution and review code before running anything.
  • amcai/myscan • ⭐ 663 • 2020-03-16 • Conf: 90.0%
  • myscan 被动扫描
  • anasbousselham/fortiscan • ⭐ 162 • 2020-11-25 • Conf: 95.0%
  • A high performance FortiGate SSL-VPN vulnerability scanning and exploitation tool.

FIRST EPSS

EPSS estimates the probability of exploitation in the next 30 days. Higher values indicate higher likelihood of real-world exploitation.

Timeline

CVE Stalker KEV MITRE GitHub FIRST (EPSS)

MITRE

CVSS

  • Score: 9.1
  • Severity: CRITICAL
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

SSVC

  • Exploitation: active
  • Automatable: yes
  • Technical Impact: partial

References

Show Raw Data
Key Remaining Key Value
containers > cna > affected > 0 > product Fortinet FortiOS, FortiProxy
containers > cna > affected > 0 > vendor Fortinet
containers > cna > affected > 0 > versions > 0 > status affected
containers > cna > affected > 0 > versions > 0 > version FortiOS 6.0.0 to 6.0.4, 5.6.3 to 5.6.7 and 5.4.6 to 5.4.12, FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7
containers > cna > datePublic 2019-05-24T00:00:00.000Z
containers > cna > descriptions > 0 > lang en
containers > cna > descriptions > 0 > value An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.3 to 5.6.7 and 5.4.6 to 5.4.12 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7 under SSL VPN web portal allows an unauthenticated attacker to download system files via special crafted HTTP resource requests.
containers > cna > metrics > 0 > cvssV3_1 > attackComplexity LOW
containers > cna > metrics > 0 > cvssV3_1 > attackVector NETWORK
containers > cna > metrics > 0 > cvssV3_1 > availabilityImpact HIGH
containers > cna > metrics > 0 > cvssV3_1 > baseScore 9.1
containers > cna > metrics > 0 > cvssV3_1 > baseSeverity CRITICAL
containers > cna > metrics > 0 > cvssV3_1 > confidentialityImpact HIGH
containers > cna > metrics > 0 > cvssV3_1 > integrityImpact NONE
containers > cna > metrics > 0 > cvssV3_1 > privilegesRequired NONE
containers > cna > metrics > 0 > cvssV3_1 > scope UNCHANGED
containers > cna > metrics > 0 > cvssV3_1 > userInteraction NONE
containers > cna > metrics > 0 > cvssV3_1 > vectorString CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
containers > cna > metrics > 0 > cvssV3_1 > version 3.1
containers > cna > problemTypes > 0 > descriptions > 0 > description Information disclosure
containers > cna > problemTypes > 0 > descriptions > 0 > lang en
containers > cna > problemTypes > 0 > descriptions > 0 > type text
containers > cna > providerMetadata > dateUpdated 2021-06-03T10:29:56.000Z
containers > cna > providerMetadata > orgId 6abe59d8-c742-4dff-8ce8-9b0ca1073da8
containers > cna > providerMetadata > shortName fortinet
containers > cna > references > 0 > tags > 0 x_refsource_CONFIRM
containers > cna > references > 0 > url https://fortiguard.com/advisory/FG-IR-18-384
containers > cna > references > 1 > tags > 0 x_refsource_CONFIRM
containers > cna > references > 1 > url https://www.fortiguard.com/psirt/FG-IR-20-233
containers > cna > x_legacyV4Record > CVE_data_meta > ASSIGNER [email protected]
containers > cna > x_legacyV4Record > CVE_data_meta > ID CVE-2018-13379
containers > cna > x_legacyV4Record > CVE_data_meta > STATE PUBLIC
containers > cna > x_legacyV4Record > affects > vendor > vendor_data > 0 > product > product_data > 0 > product_name Fortinet FortiOS, FortiProxy
containers > cna > x_legacyV4Record > affects > vendor > vendor_data > 0 > product > product_data > 0 > version > version_data > 0 > version_value FortiOS 6.0.0 to 6.0.4, 5.6.3 to 5.6.7 and 5.4.6 to 5.4.12, FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7
containers > cna > x_legacyV4Record > affects > vendor > vendor_data > 0 > vendor_name Fortinet
containers > cna > x_legacyV4Record > data_format MITRE
containers > cna > x_legacyV4Record > data_type CVE
containers > cna > x_legacyV4Record > data_version 4.0
containers > cna > x_legacyV4Record > description > description_data > 0 > lang eng
containers > cna > x_legacyV4Record > description > description_data > 0 > value An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.3 to 5.6.7 and 5.4.6 to 5.4.12 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7 under SSL VPN web portal allows an unauthenticated attacker to download system files via special crafted HTTP resource requests.
containers > cna > x_legacyV4Record > impact > cvss > attackComplexity Low
containers > cna > x_legacyV4Record > impact > cvss > attackVector Network
containers > cna > x_legacyV4Record > impact > cvss > availabilityImpact High
containers > cna > x_legacyV4Record > impact > cvss > baseScore 8.9
containers > cna > x_legacyV4Record > impact > cvss > baseSeverity High
containers > cna > x_legacyV4Record > impact > cvss > confidentialityImpact High
containers > cna > x_legacyV4Record > impact > cvss > integrityImpact None
containers > cna > x_legacyV4Record > impact > cvss > privilegesRequired None
containers > cna > x_legacyV4Record > impact > cvss > scope Unchanged
containers > cna > x_legacyV4Record > impact > cvss > userInteraction None
containers > cna > x_legacyV4Record > impact > cvss > vectorString CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
containers > cna > x_legacyV4Record > impact > cvss > version 3.1
containers > cna > x_legacyV4Record > problemtype > problemtype_data > 0 > description > 0 > lang eng
containers > cna > x_legacyV4Record > problemtype > problemtype_data > 0 > description > 0 > value Information disclosure
containers > cna > x_legacyV4Record > references > reference_data > 0 > name https://fortiguard.com/advisory/FG-IR-18-384
containers > cna > x_legacyV4Record > references > reference_data > 0 > refsource CONFIRM
containers > cna > x_legacyV4Record > references > reference_data > 0 > url https://fortiguard.com/advisory/FG-IR-18-384
containers > cna > x_legacyV4Record > references > reference_data > 1 > name https://www.fortiguard.com/psirt/FG-IR-20-233
containers > cna > x_legacyV4Record > references > reference_data > 1 > refsource CONFIRM
containers > cna > x_legacyV4Record > references > reference_data > 1 > url https://www.fortiguard.com/psirt/FG-IR-20-233
containers > adp > 0 > providerMetadata > orgId af854a3a-2127-422b-91ae-364da2661108
containers > adp > 0 > providerMetadata > shortName CVE
containers > adp > 0 > providerMetadata > dateUpdated 2024-08-05T09:00:35.028Z
containers > adp > 0 > title CVE Program Container
containers > adp > 0 > references > 0 > tags > 0 x_refsource_CONFIRM
containers > adp > 0 > references > 0 > tags > 1 x_transferred
containers > adp > 0 > references > 0 > url https://fortiguard.com/advisory/FG-IR-18-384
containers > adp > 0 > references > 1 > tags > 0 x_refsource_CONFIRM
containers > adp > 0 > references > 1 > tags > 1 x_transferred
containers > adp > 0 > references > 1 > url https://www.fortiguard.com/psirt/FG-IR-20-233
containers > adp > 1 > metrics > 0 > other > type ssvc
containers > adp > 1 > metrics > 0 > other > content > id CVE-2018-13379
containers > adp > 1 > metrics > 0 > other > content > role CISA Coordinator
containers > adp > 1 > metrics > 0 > other > content > options > 0 > Exploitation active
containers > adp > 1 > metrics > 0 > other > content > options > 1 > Automatable yes
containers > adp > 1 > metrics > 0 > other > content > options > 2 > Technical Impact partial
containers > adp > 1 > metrics > 0 > other > content > version 2.0.3
containers > adp > 1 > metrics > 0 > other > content > timestamp 2024-10-23T13:32:05.098252Z
containers > adp > 1 > metrics > 1 > other > type kev
containers > adp > 1 > metrics > 1 > other > content > dateAdded 2021-11-03
containers > adp > 1 > metrics > 1 > other > content > reference https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-13379
containers > adp > 1 > references > 0 > url https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-13379
containers > adp > 1 > references > 0 > tags > 0 government-resource
containers > adp > 1 > problemTypes > 0 > descriptions > 0 > lang en
containers > adp > 1 > problemTypes > 0 > descriptions > 0 > type CWE
containers > adp > 1 > problemTypes > 0 > descriptions > 0 > cweId CWE-22
containers > adp > 1 > problemTypes > 0 > descriptions > 0 > description CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
containers > adp > 1 > timeline > 0 > time 2021-11-03T00:00:00.000Z
containers > adp > 1 > timeline > 0 > lang en
containers > adp > 1 > timeline > 0 > value CVE-2018-13379 added to CISA KEV
containers > adp > 1 > title CISA ADP Vulnrichment
containers > adp > 1 > providerMetadata > orgId 134c704f-9b21-4f2e-91b3-4a467353bcc0
containers > adp > 1 > providerMetadata > shortName CISA-ADP
containers > adp > 1 > providerMetadata > dateUpdated 2025-10-21T23:45:35.558Z
cveMetadata > assignerOrgId 6abe59d8-c742-4dff-8ce8-9b0ca1073da8
cveMetadata > assignerShortName fortinet
cveMetadata > cveId CVE-2018-13379
cveMetadata > datePublished 2019-06-04T20:18:08.000Z
cveMetadata > dateReserved 2018-07-06T00:00:00.000Z
cveMetadata > dateUpdated 2025-10-21T23:45:35.558Z
cveMetadata > state PUBLISHED
dataType CVE_RECORD
dataVersion 5.1