CVE-2018-13379
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.3 to 5.6.7 and 5.4.6 to 5.4.12 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7 under SSL VPN web portal allows an unauthenticated attacker to download system files via special crafted HTTP resource requests.
Activement exploitée
- Dans le catalogue CISA des vulnérabilités exploitées depuis le 3 nov. 2021
- Les agences fédérales américaines doivent la corriger avant le 3 mai 2022 (BOD 22-01)
- Première attaque observée 119 jours après la divulgation
- Confirmée par des capteurs, pas seulement par des signalements
- Utilisée dans des campagnes de rançongiciel
Apply updates per vendor instructions.
Source : CISA KEV · 1 sept. 2026 1 sept. 2026 31 août 2026 30 août 2026 29 août 2026 28 août 2026
Score CVSS9.1 / 10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:HType de faiblesse (CWE)CWE-22, CWE-22
Éditeursfortinet
Produits concernés
| Éditeurs | Prodotto | Versioni |
|---|---|---|
| fortinet | fortiproxy | < 1.2.9 |
| fortinet | fortios | < 5.4.13 |
Articles liés
This product uses the NVD API but is not endorsed or certified by the NVD.
