CVE-2018-13379

CRITICAL9.1Published on June 4, 2019

An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.3 to 5.6.7 and 5.4.6 to 5.4.12 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7 under SSL VPN web portal allows an unauthenticated attacker to download system files via special crafted HTTP resource requests.

Actively exploited

  • In the CISA exploited-vulnerabilities catalogue since Nov 3, 2021
  • US federal agencies must remediate it by May 3, 2022 (BOD 22-01)
  • First attack observed 119 days after disclosure
  • Confirmed by sensors, not only by reports
  • Used in ransomware campaigns

Apply updates per vendor instructions.

Source: CISA KEV · Sep 1, 2026 Sep 1, 2026 Aug 31, 2026 Aug 30, 2026 Aug 29, 2026 Aug 28, 2026

CVSS score9.1 / 10CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Weakness type (CWE)CWE-22, CWE-22
Vendorsfortinet

Affected products

VendorsProdottoVersioni
fortinetfortiproxy< 1.2.9
fortinetfortios< 5.4.13

Related articles

This product uses the NVD API but is not endorsed or certified by the NVD.

CVE database