Skip to content
COOEY

EXPOSURES › CVE-2018-13379

CVE-2018-13379

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2018-13379 ↗
⌖ EXPLOITED IN THE WILD SHAME 72/100 ransomwareexploited-in-wildunpatched

Fortinet's FortiOS allowed unauthenticated attackers to download system files via a path traversal vulnerability, actively exploited in the wild and linked to ransomware activity.

A path traversal flaw in Fortinet FortiOS SSL VPN allowed unauthorized access to system files, potentially enabling data exfiltration and system compromise. DIB organizations using FortiOS must immediately verify patching and review access controls to prevent exploitation and maintain CMMC compliance. This highlights the importance of vulnerability management and timely patching.

Shame score — The vulnerability's ease of exploitation and active exploitation by ransomware groups demonstrates a significant failure in secure coding practices and risk management.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Fortinet FortiOS SSL VPN web portal contains a path traversal vulnerability that may allow an unauthenticated attacker to download FortiOS system files through specially crafted HTTP resource requests.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.70
cooey ↗ severe-fallout -1.00
"…"
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.