CVE-2018-13379
Description
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.3 to 5.6.7 and 5.4.6 to 5.4.12 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7 under SSL VPN web portal allows an unauthenticated attacker to download system files via special crafted HTTP resource requests.
In plain language
AI Act nowThis Fortinet SSL VPN web portal bug lets an attacker, without logging in, download sensitive system files from the internet-facing appliance—so you should treat it as urgent and patch if you run an affected version.
CVE-2018-13379 is an unauthenticated path traversal in the Fortinet SSL VPN web portal that allows remote attackers to read arbitrary system files by sending crafted HTTP requests; it has been used in real ransomware activity and is addressed by vendor fixes.
What to do now
- Check whether your Fortinet device is running a FortiOS/ FortiProxy version that matches the affected ranges (FortiOS 6.0.0–6.0.4, 5.6.3–5.6.7, 5.4.6–5.4.12; FortiProxy 2.0.0 and 1.2.0–1.2.8 and 1.1.0–1.1.6 and 1.0.0–1.0.7).
- Confirm the SSL VPN web portal is enabled and reachable from the network you expose to the internet.
- If you are affected, upgrade immediately to the fixed versions: FortiOS 5.4.13 (for the 5.4 branch) or newer per vendor guidance, and FortiProxy 1.2.9.
- Until patched, restrict network access so SSL VPN web access is not broadly reachable from the internet, and follow the vendor advisory workarounds.
- Review logs for suspicious unauthenticated requests to the SSL VPN web portal and any unusual downloads of system files; escalate investigation if you see patterns consistent with exploitation.
1. For FortiProxy: upgrade to 1.2.9
2. For FortiOS: upgrade to 5.4.13CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:NIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Apply updates per vendor instructions.
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2018-13379 and every CVE in our database. Create a free account — no credit card required.
Create Free Account