CVE-2018-13382
גבוהה 7.5 מנוצלת בשטח (KEV) בשימוש בכופרה
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Fortinet FortiOS and FortiProxy Improper Authorization
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
An Improper Authorization vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8 and 5.4.1 to 5.4.10 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7 under SSL VPN web portal allows an unauthenticated attacker to modify the password of an SSL VPN web portal user via specially crafted HTTP requests
מדדים
- CVSS 3.1
-
7.5 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N - EPSS — סבירות ניצול
- 82% (אחוזון 100) נכון ל-11/8/2026
- CWE
- CWE-863
מוצרים מושפעים
fortinet: fortiproxy; fortinet: fortios
קישורים
- https://fortiguard.com/advisory/FG-IR-18-389 Vendor Advisory
- https://www.fortiguard.com/psirt/FG-IR-20-231 Vendor Advisory
- https://fortiguard.com/advisory/FG-IR-18-389 Vendor Advisory
- https://www.fortiguard.com/psirt/FG-IR-20-231 Vendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-201… US Government Resource