CVE-2018-13383
Description
A heap buffer overflow in Fortinet FortiOS 6.0.0 through 6.0.4, 5.6.0 through 5.6.10, 5.4.0 through 5.4.12, 5.2.14 and earlier and FortiProxy 2.0.0, 1.2.8 and earlier in the SSL VPN web portal may cause the SSL VPN web service termination for logged in users due to a failure to properly handle javascript href data when proxying webpages.
In plain language
AI Act nowCVE-2018-13383 is a Fortinet SSL VPN web portal flaw where a logged-in attacker can send malicious web content and cause the VPN web service to crash; if you run FortiOS/FortiProxy for SSL VPN, you should fix it now.
CVE-2018-13383 is a heap buffer overflow (CWE-787) in Fortinet FortiOS and FortiProxy SSL VPN web portal proxying that can be triggered by a logged-in user by supplying malicious JavaScript href data, leading to service termination; it is listed in CISA KEV and was used in ransomware campaigns, so affected systems should be updated per vendor guidance.
What to do now
- Check whether your business uses Fortinet SSL VPN web portal on “fortinet fortios and fortiproxy” (FortiOS and/or FortiProxy) and whether your deployed versions fall within the affected ranges.
- Confirm you have logged-in SSL VPN web portal users and whether any account could be abused (lost credentials, shared accounts, weak passwords).
- Upgrade FortiProxy to version 1.2.9 or later.
- Upgrade FortiOS to version 5.2.15 or later.
- If you cannot upgrade immediately, apply the vendor workaround guidance from the linked FortiGuard advisories and plan an urgent upgrade as the permanent fix.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:LPrivileges RequiredUI:NUser InteractionS:UScopeC:NConfidentialityI:NIntegrityA:LAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Apply updates per vendor instructions.
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2018-13383 and every CVE in our database. Create a free account — no credit card required.
Create Free Account