CyberSec.Space Logo
Back to CVE Browser

CVE-2018-13379

Known Exploited (CISA KEV)CRITICAL
9.1
CVSS Severity Score
EPSS Score30.2630%
EPSS Percentile90.34th
PublishedJun 4, 2019
Last ModifiedOct 24, 2025

Vulnerability Description

An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.3 to 5.6.7 and 5.4.6 to 5.4.12 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7 under SSL VPN web portal allows an unauthenticated attacker to download system files via special crafted HTTP resource requests.

Affected Platforms (CPE)

πŸ“¦
Fortinet

Fortiproxy

< 1.2.9
πŸ“¦
Fortinet

Fortiproxy

= 2.0.0
πŸ’»
Fortinet

Fortios

>= 5.4.6 and < 5.4.13
πŸ’»
Fortinet

Fortios

>= 5.6.3 and < 5.6.8
πŸ’»
Fortinet

Fortios

>= 6.0.0 and < 6.0.5

References & Advisories

Related Vulnerabilities