EXPOSURES › CVE-2018-13382
CVE-2018-13382
CRITICAL ⌖ ON CISA KEV · EXPLOITEDUnauthenticated attackers could modify passwords on Fortinet SSL VPN portals due to improper authorization vulnerabilities, actively exploited in the wild and linked to ransomware activity.
Fortinet FortiOS and FortiProxy devices suffered from a critical improper authorization flaw allowing password modification without authentication. This exposes DIB organizations using these devices to unauthorized access and potential data compromise, impacting CMMC/NIST 800-171 compliance (specifically access control). Immediate patching and access control review are essential.
Shame score — The vulnerability allowed unauthorized password modification, actively exploited and linked to ransomware, demonstrating a significant failure in access control and a lack of basic security practices.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
An Improper Authorization vulnerability in Fortinet FortiOS and FortiProxy under SSL VPN web portal allows an unauthenticated attacker to modify the password.