LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2018-13382: Fortinet FortiOS and FortiProxy Improper Authorization

RBRecent Breaches Vulnerability Intelligence·Jan 10, 2022
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Jul 10, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2018-13382 to its Known Exploited Vulnerabilities catalog on Jan 10, 2022, with a federal patch deadline of Jul 10, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

An Improper Authorization vulnerability in Fortinet FortiOS and FortiProxy under SSL VPN web portal allows an unauthenticated attacker to modify the password.

CVE-2018-13382 is an improper authorization flaw in Fortinet FortiOS and FortiProxy that affects the SSL VPN web portal. An unauthenticated attacker can modify a password through that interface. Because the issue sits on a common remote-access path and has been used in ransomware operations, organizations running these products should treat it as a priority for inventory, patching, and monitoring.

Public detail is limited to the product family, the SSL VPN web portal surface, and the ability for an unauthenticated party to change a password. Confirm exact affected builds, fixed releases, and any configuration prerequisites against the vendor advisory before acting.

How it works

The weakness is classified as CWE-285 (Improper Authorization). In products that expose an SSL VPN web portal, authorization checks that should restrict password-change operations to authenticated, authorized users are not enforced correctly. An attacker who can reach the portal can therefore attempt to alter a password without first proving legitimate access.

At a high level, the abuse path is: locate a reachable SSL VPN web portal on a FortiOS or FortiProxy device, then invoke the password-modification functionality in a way that bypasses the missing authorization control. Successful abuse can lock out legitimate users or give the attacker a foothold for further access. Exact request formats, parameters, or preconditions are not provided here; treat any public proof-of-concept material with caution and validate behavior only in controlled lab conditions against the vendor’s description.

Am I affected? How to find it in your systems

FortiOS commonly runs on Fortinet firewalls and security appliances that terminate SSL VPN; FortiProxy is used in proxy and secure web gateway deployments. Both may expose an SSL VPN web portal to the internet or to broad internal networks.

If you cannot determine portal exposure or version from configuration alone, treat internet-facing Fortinet SSL VPN instances as in-scope until proven otherwise.

How to remediate

Patch first. Apply the updates Fortinet has issued for FortiOS and FortiProxy per the vendor instructions referenced in the CISA required action. Confirm the fixed release for your exact build in the official advisory and schedule maintenance windows accordingly.

If you can't patch immediately

Until the vendor update is applied, reduce the attack surface and increase detection.

These steps are compensating controls only; they do not replace the vendor patch.

If your data may have been exposed

Actively exploited vulnerabilities, including those with known ransomware use, frequently lead to account takeover and broader breaches. If your SSL VPN portal was reachable and unpatched, assume passwords may have been altered and investigate for unauthorized access, lateral movement, and data staging. Reset affected credentials, review privileged accounts, and follow your incident-response plan. You can run a free exposure scan of your email addresses against known breach data to see whether associated credentials have appeared in prior incidents and to prioritize further monitoring.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedFortinet · FortiOS and FortiProxy
WeaknessCWE-285
Added to CISA KEVJan 10, 2022
Federal patch deadlineJul 10, 2022
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities