Skip to content
COOEY

EXPOSURES › CVE-2018-13382

CVE-2018-13382

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-01-10 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2018-13382 ↗
⌖ EXPLOITED IN THE WILD SHAME 72/100 ransomwareexploited-in-wildunpatched

Unauthenticated attackers could modify passwords on Fortinet SSL VPN portals due to improper authorization vulnerabilities, actively exploited in the wild and linked to ransomware activity.

Fortinet FortiOS and FortiProxy devices suffered from a critical improper authorization flaw allowing password modification without authentication. This exposes DIB organizations using these devices to unauthorized access and potential data compromise, impacting CMMC/NIST 800-171 compliance (specifically access control). Immediate patching and access control review are essential.

Shame score — The vulnerability allowed unauthorized password modification, actively exploited and linked to ransomware, demonstrating a significant failure in access control and a lack of basic security practices.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

An Improper Authorization vulnerability in Fortinet FortiOS and FortiProxy under SSL VPN web portal allows an unauthenticated attacker to modify the password.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.