CVE-2018-13382
An Improper Authorization vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8 and 5.4.1 to 5.4.10 and FortiProxy 2.0.0, 1.2.0 to...
Basic Information
- CVE State
- PUBLISHED
- Reserved Date
- July 06, 2018
- Published Date
- June 04, 2019
- Last Updated
- October 23, 2024
- Vendor
- Fortinet
- Product
- Fortinet FortiOS, FortiProxy
- Description
- An Improper Authorization vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8 and 5.4.1 to 5.4.10 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7 under SSL VPN web portal allows an unauthenticated attacker to modify the password of an SSL VPN web portal user via specially crafted HTTP requests
CVSS Scores
CVSS v3.1
9.1 - CRITICAL
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
SSVC Information
- Exploitation
- active
- Automatable
- Yes
- Technical Impact
- total
References
Known Exploited Vulnerability Information
Source | Added Date |
---|---|
CISA | 2022-01-10 00:00:00 UTC |
Potential Proof of Concepts
Warning: These PoCs have not been tested and could contain malware. Use at your own risk.
cojoben/CVE-2018-13382
Type: github • Created: 2025-02-26 14:22:05 UTC • Stars: 0
milo2012/CVE-2018-13382
Type: github • Created: 2019-08-11 11:13:44 UTC • Stars: 148
CVE-2018-13382