CVE-2018-13382
KEV ransomwaremassUnauthenticated SSL VPN Account-Takeover Flaw in Fortinet FortiOS and FortiProxy
CISA: Fortinet FortiOS and FortiProxy Improper Authorization
CVE-2018-13382 is an improper authorization flaw (CWE-863) in the SSL VPN web portal of Fortinet FortiOS and FortiProxy that fails to properly authorize password-change requests. An unauthenticated attacker who can reach the SSL VPN web portal can send specially crafted HTTP requests to modify the password of an SSL VPN web-portal user without knowing the existing credentials. This effectively hands the attacker control of the victim's VPN account, enabling login through the portal and potential follow-on access to the internal network, consistent with the integrity-only CVSS 3.1 score of 7.5 (High). Any organization running affected versions - FortiOS 6.0.0-6.0.4, 5.6.0-5.6.8 or 5.4.1-5.4.10, or FortiProxy 2.0.0, 1.2.0-1.2.8, 1.1.0-1.1.6 or 1.0.0-1.0.7 - with the SSL VPN web portal enabled is affected. The flaw is actively exploited: it was added to CISA's KEV catalog on 2022-01-10 with known ransomware use, EPSS estimates an 81.7% probability of exploitation within 30 days, and NSA/NCSC advisories warn that APT groups are exploiting VPN vulnerabilities of this kind.
What to do: Apply updates to all affected FortiOS and FortiProxy deployments per Fortinet's instructions, as this is the CISA KEV required action, prioritizing internet-facing SSL VPN portals. Until patched, limit exposure of the SSL VPN web portal and audit authentication logs for unexpected password changes or unauthenticated requests to the portal. Given known ransomware and APT exploitation, force a password reset on VPN accounts whose credentials may have been tampered with.
| Fortinet FortiOS | 6.0.0-6.0.4, 5.6.0-5.6.8, 5.4.1-5.4.10 |
| Fortinet FortiProxy | 2.0.0, 1.2.0-1.2.8, 1.1.0-1.1.6, 1.0.0-1.0.7 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An Improper Authorization vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8 and 5.4.1 to 5.4.10 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7 under SSL VPN web portal allows an unauthenticated attacker to modify the password of an SSL VPN web portal user via specially crafted HTTP requests
- Affected
- Fortinet FortiOS and FortiProxy
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Known
- Vendors
- fortinet
- Products
- fortiproxy, fortios
- Weakness
- CWE-863
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N