ZeroHour

CVE-2018-13382

KEV ransomwaremass

Unauthenticated SSL VPN Account-Takeover Flaw in Fortinet FortiOS and FortiProxy

CISA: Fortinet FortiOS and FortiProxy Improper Authorization

CVSS 3.1
7.5 high
EPSS
82%p100
Published
()
KEV added
AI analysis

CVE-2018-13382 is an improper authorization flaw (CWE-863) in the SSL VPN web portal of Fortinet FortiOS and FortiProxy that fails to properly authorize password-change requests. An unauthenticated attacker who can reach the SSL VPN web portal can send specially crafted HTTP requests to modify the password of an SSL VPN web-portal user without knowing the existing credentials. This effectively hands the attacker control of the victim's VPN account, enabling login through the portal and potential follow-on access to the internal network, consistent with the integrity-only CVSS 3.1 score of 7.5 (High). Any organization running affected versions - FortiOS 6.0.0-6.0.4, 5.6.0-5.6.8 or 5.4.1-5.4.10, or FortiProxy 2.0.0, 1.2.0-1.2.8, 1.1.0-1.1.6 or 1.0.0-1.0.7 - with the SSL VPN web portal enabled is affected. The flaw is actively exploited: it was added to CISA's KEV catalog on 2022-01-10 with known ransomware use, EPSS estimates an 81.7% probability of exploitation within 30 days, and NSA/NCSC advisories warn that APT groups are exploiting VPN vulnerabilities of this kind.

What to do: Apply updates to all affected FortiOS and FortiProxy deployments per Fortinet's instructions, as this is the CISA KEV required action, prioritizing internet-facing SSL VPN portals. Until patched, limit exposure of the SSL VPN web portal and audit authentication logs for unexpected password changes or unauthenticated requests to the portal. Given known ransomware and APT exploitation, force a password reset on VPN accounts whose credentials may have been tampered with.

Affected
Fortinet FortiOS6.0.0-6.0.4, 5.6.0-5.6.8, 5.4.1-5.4.10
Fortinet FortiProxy2.0.0, 1.2.0-1.2.8, 1.1.0-1.1.6, 1.0.0-1.0.7
Estimated exposure
masshundreds of thousands of internet-exposed FortiGate/FortiProxy SSL VPN endpoints (estimate) — FortiGate and FortiProxy SSL VPN gateways are among the most widely deployed enterprise edge/remote-access devices, and public internet-wide scans have repeatedly counted on the order of hundreds of thousands of exposed Fortinet SSL VPN…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An Improper Authorization vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8 and 5.4.1 to 5.4.10 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7 under SSL VPN web portal allows an unauthenticated attacker to modify the password of an SSL VPN web portal user via specially crafted HTTP requests

CISA Known Exploited Vulnerability
Affected
Fortinet FortiOS and FortiProxy
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
fortinet
Products
fortiproxy, fortios
Weakness
CWE-863
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

In the news