CVE-2018-13383
KEV ransomwaremassOut-of-Bounds Write in Fortinet FortiOS and FortiProxy SSL VPN Web Service
CISA: Fortinet FortiOS and FortiProxy Out-of-bounds Write
CVE-2018-13383 is a heap buffer overflow (out-of-bounds write, CWE-787) in the SSL VPN web portal of Fortinet FortiOS and FortiProxy. It is triggered when a logged-in SSL VPN user's web session processes crafted JavaScript supplied by a remote site, corrupting heap memory in the SSL VPN web service. An attacker can crash the SSL VPN web service, terminating access for logged-in users, and Fortinet's advisory indicates the memory corruption may allow arbitrary code execution via a crafted JavaScript payload. Organizations running affected FortiOS releases on FortiGate appliances with the SSL VPN web portal enabled, and organizations running FortiProxy secure web gateways, are affected. Exploitation is active: the flaw was added to CISA KEV on 2022-01-10 with known ransomware use, the required action is to apply vendor updates, and EPSS assigns a 33.6% 30-day exploitation probability (98th percentile).
What to do: Apply Fortinet's fixed releases per the vendor advisory (FortiGate/FortiOS: 6.2.1+, 6.0.5+, 5.6.8+, or 5.4.11+ as applicable; FortiProxy: 2.0.1+ or 1.2.9+), consistent with the CISA KEV required action. Until patched, restrict exposure of the SSL VPN web portal to the internet and monitor the appliance for signs of compromise, given the known ransomware use. Prioritize internet-facing SSL VPN endpoints in remediation ordering because of the elevated EPSS score.
| Fortinet FortiOS | Multiple releases including 6.2.0, 6.0.0-6.0.4, 5.6.0-5.6.7, and 5.4.0-5.4.10 (ranges per Fortinet advisory; source data does not specify versions) |
| Fortinet FortiProxy | 2.0.0 and 1.2.x releases (ranges per Fortinet advisory; source data does not specify versions) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A heap buffer overflow in Fortinet FortiOS 6.0.0 through 6.0.4, 5.6.0 through 5.6.10, 5.4.0 through 5.4.12, 5.2.14 and earlier and FortiProxy 2.0.0, 1.2.8 and earlier in the SSL VPN web portal may cause the SSL VPN web service termination for logged in users due to a failure to properly handle javascript href data when proxying webpages.
- Affected
- Fortinet FortiOS and FortiProxy
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Known
- Vendors
- fortinet
- Products
- fortiproxy, fortios
- Weakness
- CWE-787
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H