PT-2019-3002 · Fortinet · Fortios+2
CVE-2018-13379
·
Published
2019-05-24
·
Updated
2026-09-09
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
FortiOS versions 6.0.0 through 6.0.4
FortiOS versions 5.6.3 through 5.6.7
FortiOS versions 5.4.6 through 5.4.12
FortiProxy version 2.0.0
FortiProxy versions 1.2.0 through 1.2.8
FortiProxy versions 1.1.0 through 1.1.6
FortiProxy versions 1.0.0 through 1.0.7
Description
A path traversal issue exists in the SSL VPN web portal due to improper limitation of a pathname to a restricted directory. This allows an unauthenticated remote attacker to download system files by sending specially crafted HTTP resource requests. Path traversal is a technique used to access files and directories that are stored outside the web root folder. Real-world exploitation has been observed by the Ghost (Cring) ransomware group to obtain VPN credentials for initial access. It is estimated that SSL-VPN access information for 87,000 FortiGate devices was disclosed due to this issue.
Recommendations
For FortiOS versions 6.0.0 through 6.0.4, 5.6.3 through 5.6.7, and 5.4.6 through 5.4.12, update the software and perform a mandatory password reset for all users to protect against previously compromised credentials.
For FortiProxy versions 2.0.0, 1.2.0 through 1.2.8, 1.1.0 through 1.1.6, and 1.0.0 through 1.0.7, update the software and perform a mandatory password reset for all users to protect against previously compromised credentials.
Exploit
Fix
DoS
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fortigate
Fortios
Fortiproxy