CVE-2018-13379
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.3 to 5.6.7 and 5.4.6 to 5.4.12 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7 under SSL VPN web portal allows an unauthenticated attacker to download system files via special crafted HTTP resource requests.
Actively exploited
- In the CISA exploited-vulnerabilities catalogue since Nov 3, 2021
- US federal agencies must remediate it by May 3, 2022 (BOD 22-01)
- First attack observed 119 days after disclosure
- Confirmed by sensors, not only by reports
- Used in ransomware campaigns
Apply updates per vendor instructions.
Source: CISA KEV · Sep 1, 2026 Sep 1, 2026 Aug 31, 2026 Aug 30, 2026 Aug 29, 2026 Aug 28, 2026
CVSS score9.1 / 10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:HWeakness type (CWE)CWE-22, CWE-22
Vendorsfortinet
Affected products
| Vendors | Prodotto | Versioni |
|---|---|---|
| fortinet | fortiproxy | < 1.2.9 |
| fortinet | fortios | < 5.4.13 |
Related articles
This product uses the NVD API but is not endorsed or certified by the NVD.
