PT-2019-3002 · Fortinet · Fortios+2
CVE-2018-13379
·
Published
2019-05-24
·
Updated
2026-06-23
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
FortiOS versions 6.0.0 through 6.0.4
FortiOS versions 5.6.3 through 5.6.7
FortiOS versions 5.4.6 through 5.4.12
FortiProxy version 2.0.0
FortiProxy versions 1.2.0 through 1.2.8
FortiProxy versions 1.1.0 through 1.1.6
FortiProxy versions 1.0.0 through 1.0.7
Description
An improper limitation of a pathname to a restricted directory, known as Path Traversal, exists within the SSL VPN web portal. This allows an unauthenticated remote attacker to download system files by sending specially crafted HTTP resource requests. In real-world incidents, this issue was exploited by the Ghost (Cring) ransomware group to obtain VPN plaintext credentials for initial access. It is reported that SSL-VPN access information for approximately 87,000 FortiGate SSL-VPN devices was disclosed due to this flaw.
Recommendations
For FortiOS versions 6.0.0 through 6.0.4, 5.6.3 through 5.6.7, and 5.4.6 through 5.4.12, update the software and perform a critical password reset for all users to protect against previously compromised credentials.
For FortiProxy versions 2.0.0, 1.2.0 through 1.2.8, 1.1.0 through 1.1.6, and 1.0.0 through 1.0.7, update the software and perform a critical password reset for all users to protect against previously compromised credentials.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fortigate
Fortios
Fortiproxy