CVE-2018-13382 PUBLISHED KEV CVSS 9.100000381469727 CRITICAL

An Improper Authorization vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8 and 5.4.1 to 5.4.10 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7 under SSL VPN web portal allows an unauthenticated attacker to modify the password of an SSL VPN web portal user via specially crafted HTTP requests

EPSS 85.99% · 99.4th percentile

Risk Scores

CVSS v3.1
9.100000381469727
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
EPSS Score
85.99%
99.4th percentile

Affected Products

VendorProductVersions
fortinetfortios6.0.0, 6.0.0, 5.4.1
FortinetFortinet FortiOS, FortiProxyFortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8, 5.4.1 to 5.4.10, FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7
fortinetfortiproxy0, 2.0.0, 0
Fortinet, Inc.FortiOS5.2.0 to 5.2.12, 5.0 and below, 5.4.0 to 5.4.6

Timeline

References

…and 8 more

Open in Interactive Console →