Skip to content
COOEY

EXPOSURES › CVE-2018-13383

CVE-2018-13383

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-01-10 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2018-13383 ↗
⌖ EXPLOITED IN THE WILD SHAME 72/100 ransomwareexploited-in-wildunpatched

Fortinet's FortiOS and FortiProxy had a critical heap buffer overflow exploited in the wild, potentially disrupting SSL VPN services for logged-in users.

A heap buffer overflow vulnerability (CVE-2018-13383) in Fortinet products allowed for service disruption via SSL VPN termination. DIB organizations using these products should verify patching status and assess potential impact to remote access. Failure to patch exposes systems to exploitation and can negatively impact CMMC compliance.

Shame score — The vulnerability was actively exploited and linked to ransomware, indicating a significant and avoidable security failure.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

A heap buffer overflow in Fortinet FortiOS and FortiProxy may cause the SSL VPN web service termination for logged in users.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.