CVE-2018-13383
בינונית 6.5 מנוצלת בשטח (KEV) בשימוש בכופרה
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Fortinet FortiOS and FortiProxy Out-of-bounds Write
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
A heap buffer overflow in Fortinet FortiOS 6.0.0 through 6.0.4, 5.6.0 through 5.6.10, 5.4.0 through 5.4.12, 5.2.14 and earlier and FortiProxy 2.0.0, 1.2.8 and earlier in the SSL VPN web portal may cause the SSL VPN web service termination for logged in users due to a failure to properly handle javascript href data when proxying webpages.
מדדים
- CVSS 3.1
-
6.5 (MEDIUM)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H - EPSS — סבירות ניצול
- 34% (אחוזון 100) נכון ל-10/8/2026
- CWE
- CWE-787
מוצרים מושפעים
fortinet: fortiproxy; fortinet: fortios
קישורים
- https://fortiguard.com/advisory/FG-IR-18-388 MitigationVendor Advisory
- https://fortiguard.com/advisory/FG-IR-20-229 Vendor Advisory
- https://fortiguard.com/advisory/FG-IR-18-388 MitigationVendor Advisory
- https://fortiguard.com/advisory/FG-IR-20-229 Vendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-201… US Government Resource