CyberSec.Space Logo
CVEブラウザに戻る

CVE-2018-13379

Known Exploited (CISA KEV)CRITICAL
9.1
CVSS Severity Score
EPSS Score30.2630%
EPSS Percentile90.34th
Published2019年6月4日
Last Modified2025年10月24日

Vulnerability Description

An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.3 to 5.6.7 and 5.4.6 to 5.4.12 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7 under SSL VPN web portal allows an unauthenticated attacker to download system files via special crafted HTTP resource requests.

Affected Platforms (CPE)

📦
Fortinet

Fortiproxy

< 1.2.9
📦
Fortinet

Fortiproxy

= 2.0.0
💻
Fortinet

Fortios

>= 5.4.6 and < 5.4.13
💻
Fortinet

Fortios

>= 5.6.3 and < 5.6.8
💻
Fortinet

Fortios

>= 6.0.0 and < 6.0.5

References & Advisories

関連する脆弱性情報