Umbra Wiki cve cve/CVE-2018-13382
Back to wiki

CVE-2018-13382 — Fortinet FortiOS and FortiProxy Improper Authorization

provenance: imported · CVE: CVE-2018-13382

CVE-2018-13382: Fortinet FortiOS and FortiProxy Improper Authorization

CISA Known Exploited Vulnerability (KEV)

Vendor / project Fortinet
Product FortiOS and FortiProxy
Date added 2022-01-10
Due date 2022-07-10
Ransomware campaign use Known

Description

An Improper Authorization vulnerability in Fortinet FortiOS and FortiProxy under SSL VPN web portal allows an unauthenticated attacker to modify the password.

Required action (CISA)

Apply updates per vendor instructions.

Notes

https://nvd.nist.gov/vuln/detail/CVE-2018-13382

References

  • NVD: https://nvd.nist.gov/vuln/detail/CVE-2018-13382
  • KEV catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog