EXPOSURES › CVE-2018-13383
CVE-2018-13383
CRITICAL ⌖ ON CISA KEV · EXPLOITEDFortinet's FortiOS and FortiProxy had a critical heap buffer overflow exploited in the wild, potentially disrupting SSL VPN services for logged-in users.
A heap buffer overflow vulnerability (CVE-2018-13383) in Fortinet products allowed for service disruption via SSL VPN termination. DIB organizations using these products should verify patching status and assess potential impact to remote access. Failure to patch exposes systems to exploitation and can negatively impact CMMC compliance.
Shame score — The vulnerability was actively exploited and linked to ransomware, indicating a significant and avoidable security failure.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A heap buffer overflow in Fortinet FortiOS and FortiProxy may cause the SSL VPN web service termination for logged in users.