LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2018-13379: Fortinet FortiOS SSL VPN Path Traversal Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 3, 2021
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
May 3, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2018-13379 to its Known Exploited Vulnerabilities catalog on Nov 3, 2021, with a federal patch deadline of May 3, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

Fortinet FortiOS SSL VPN web portal contains a path traversal vulnerability that may allow an unauthenticated attacker to download FortiOS system files through specially crafted HTTP resource…

CVE-2018-13379 is a path traversal weakness in the SSL VPN web portal of Fortinet FortiOS. An unauthenticated attacker can send specially crafted HTTP resource requests to download FortiOS system files. Because the flaw sits on a network-facing VPN service and has been used in ransomware operations, it matters to any organization that exposes FortiOS SSL VPN to the internet or untrusted networks.

Public detail is limited to the CISA description and the CWE-22 classification; exact affected builds, scoring, and exploit mechanics must be confirmed against the vendor advisory. The required action is to apply updates per vendor instructions.

How it works

The vulnerability belongs to the path-traversal class (CWE-22). In products that serve files or resources over HTTP, insufficient validation of user-supplied path elements can let an attacker escape the intended directory and read arbitrary files on the system.

In this case the FortiOS SSL VPN web portal fails to properly constrain resource requests. An unauthenticated remote attacker crafts HTTP requests that traverse outside the portal’s normal document root and retrieve FortiOS system files. Those files may contain configuration data, credentials, or other sensitive material that can be used for further access. No authentication is required, so the attack surface is any reachable SSL VPN portal instance that has not been patched or mitigated.

Am I affected? How to find it in your systems

FortiOS is the operating system that runs on Fortinet FortiGate firewalls and related appliances. The SSL VPN web portal is commonly enabled to give remote users secure access. Inventory every FortiGate or FortiOS device that presents an SSL VPN service on any interface, especially those reachable from the internet or partner networks.

If logging is incomplete, treat any unpatched, internet-facing SSL VPN portal as potentially exposed until proven otherwise.

How to remediate

Patch first. Apply the FortiOS updates specified by Fortinet for CVE-2018-13379 exactly as described in the vendor advisory. CISA’s required action is to apply updates per vendor instructions; verify the fixed version and any prerequisite steps directly from that advisory before deployment.

If you can't patch immediately

Until the vendor update can be applied, reduce exposure with compensating controls:

These measures lower risk but do not replace the vendor patch.

If your data may have been exposed

Actively exploited vulnerabilities of this type have been leveraged in ransomware campaigns. If logs or other evidence suggest system files were downloaded, treat the incident as a potential breach: isolate affected devices, preserve logs, rotate credentials, and follow your incident-response plan. You can also run a free exposure scan of your email addresses against known breach data sets to check whether associated accounts appear in prior compromises.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedFortinet · FortiOS
WeaknessCWE-22
Added to CISA KEVNov 3, 2021
Federal patch deadlineMay 3, 2022
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities