ZeroHour

CVE-2018-13383

KEV ransomwaremass

Out-of-Bounds Write in Fortinet FortiOS and FortiProxy SSL VPN Web Service

CISA: Fortinet FortiOS and FortiProxy Out-of-bounds Write

CVSS 3.1
6.5 medium
EPSS
34%p98
Published
()
KEV added
AI analysis

CVE-2018-13383 is a heap buffer overflow (out-of-bounds write, CWE-787) in the SSL VPN web portal of Fortinet FortiOS and FortiProxy. It is triggered when a logged-in SSL VPN user's web session processes crafted JavaScript supplied by a remote site, corrupting heap memory in the SSL VPN web service. An attacker can crash the SSL VPN web service, terminating access for logged-in users, and Fortinet's advisory indicates the memory corruption may allow arbitrary code execution via a crafted JavaScript payload. Organizations running affected FortiOS releases on FortiGate appliances with the SSL VPN web portal enabled, and organizations running FortiProxy secure web gateways, are affected. Exploitation is active: the flaw was added to CISA KEV on 2022-01-10 with known ransomware use, the required action is to apply vendor updates, and EPSS assigns a 33.6% 30-day exploitation probability (98th percentile).

What to do: Apply Fortinet's fixed releases per the vendor advisory (FortiGate/FortiOS: 6.2.1+, 6.0.5+, 5.6.8+, or 5.4.11+ as applicable; FortiProxy: 2.0.1+ or 1.2.9+), consistent with the CISA KEV required action. Until patched, restrict exposure of the SSL VPN web portal to the internet and monitor the appliance for signs of compromise, given the known ransomware use. Prioritize internet-facing SSL VPN endpoints in remediation ordering because of the elevated EPSS score.

Affected
Fortinet FortiOSMultiple releases including 6.2.0, 6.0.0-6.0.4, 5.6.0-5.6.7, and 5.4.0-5.4.10 (ranges per Fortinet advisory; source data does not specify versions)
Fortinet FortiProxy2.0.0 and 1.2.x releases (ranges per Fortinet advisory; source data does not specify versions)
Estimated exposure
masslikely several hundred thousand internet-exposed FortiGate SSL VPN portals and FortiProxy gateways, out of a Fortinet installed base in the millions of devices — Fortinet is the largest firewall/UTM vendor by unit shipments with a multi-million-device installed base, SSL VPN is commonly enabled on those gateways, and public internet scans have repeatedly counted hundreds of thousands of exposed…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A heap buffer overflow in Fortinet FortiOS 6.0.0 through 6.0.4, 5.6.0 through 5.6.10, 5.4.0 through 5.4.12, 5.2.14 and earlier and FortiProxy 2.0.0, 1.2.8 and earlier in the SSL VPN web portal may cause the SSL VPN web service termination for logged in users due to a failure to properly handle javascript href data when proxying webpages.

CISA Known Exploited Vulnerability
Affected
Fortinet FortiOS and FortiProxy
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
fortinet
Products
fortiproxy, fortios
Weakness
CWE-787
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

In the news