PT-2019-3002 · Fortinet · Fortios+2

CVE-2018-13379

·

Published

2019-05-24

·

Updated

2026-09-09

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FortiOS versions 6.0.0 through 6.0.4 FortiOS versions 5.6.3 through 5.6.7 FortiOS versions 5.4.6 through 5.4.12 FortiProxy version 2.0.0 FortiProxy versions 1.2.0 through 1.2.8 FortiProxy versions 1.1.0 through 1.1.6 FortiProxy versions 1.0.0 through 1.0.7
Description A path traversal issue exists in the SSL VPN web portal due to improper limitation of a pathname to a restricted directory. This allows an unauthenticated remote attacker to download system files by sending specially crafted HTTP resource requests. Path traversal is a technique used to access files and directories that are stored outside the web root folder. Real-world exploitation has been observed by the Ghost (Cring) ransomware group to obtain VPN credentials for initial access. It is estimated that SSL-VPN access information for 87,000 FortiGate devices was disclosed due to this issue.
Recommendations For FortiOS versions 6.0.0 through 6.0.4, 5.6.3 through 5.6.7, and 5.4.6 through 5.4.12, update the software and perform a mandatory password reset for all users to protect against previously compromised credentials. For FortiProxy versions 2.0.0, 1.2.0 through 1.2.8, 1.1.0 through 1.1.6, and 1.0.0 through 1.0.7, update the software and perform a mandatory password reset for all users to protect against previously compromised credentials.

Exploit

Fix

DoS

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-02981
CVE-2018-13379

Affected Products

Fortigate
Fortios
Fortiproxy