CVE-2018-13382
KEV RANSOMWARECRITICAL 9.1EPSS 81.7%
An Improper Authorization vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8 and 5.4.1 to 5.4.10 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7 under SSL VPN web portal allows an unauthenticated attacker to modify the password of an SSL VPN web portal user via specially crafted HTTP requests
- CVSS v3.1
- 7.5 HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N - CVSS v3.1
- 9.1 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N - CVSS v2.0
- 5.0 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N - EPSS
- 81.69% chance of exploitation in the next 30 days, 100th percentile
- CISA KEV
- added 2022-01-10, used in ransomware campaigns
- Published
- 2019-06-04
- Updated
- 2025-10-21
Proof-of-concept exploits (4)
- cojoben/CVE-2018-133820★ · 2025-02-26
- dhn/exploits56★ · 2020-06-02
- milo2012/CVE-2018-13382146★ · 2019-08-13
- tumikoto/Exploit-FortinetMagicBackdoor1★ · 2021-04-28