CVE-2018-13379
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.3 to 5.6.7 and 5.4.6 to 5.4.12 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7 under SSL VPN web portal allows an unauthenticated attacker to download system files via special crafted HTTP resource requests.
Aktiv ausgenutzt
- Seit dem 3. Nov. 2021 im CISA-Katalog ausgenutzter Schwachstellen
- US-Bundesbehörden müssen sie bis zum 3. Mai 2022 beheben (BOD 22-01)
- Erster Angriff 119 Tage nach der Veröffentlichung beobachtet
- Durch Sensoren bestätigt, nicht nur durch Meldungen
- In Ransomware-Kampagnen eingesetzt
Apply updates per vendor instructions.
Quelle: CISA KEV · 1. Sept. 2026 1. Sept. 2026 31. Aug. 2026 30. Aug. 2026 29. Aug. 2026 28. Aug. 2026
CVSS-Score9.1 / 10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:HSchwachstellentyp (CWE)CWE-22, CWE-22
Herstellerfortinet
Betroffene Produkte
| Hersteller | Prodotto | Versioni |
|---|---|---|
| fortinet | fortiproxy | < 1.2.9 |
| fortinet | fortios | < 5.4.13 |
Verwandte Artikel
This product uses the NVD API but is not endorsed or certified by the NVD.
