Vulnerability record · CVE-2018-13379 · published 4 June 2019
CVE-2018-13379: Fortinet FortiOS and FortiProxy SSL VPN path traversal allows unauthenticated file download
Fortinet · Fortiproxy
FortiOS and FortiProxy SSL VPN web portals fail to properly restrict pathnames, allowing crafted HTTP requests to traverse directories and download system files. Because the flaw is reachable without authentication, it exposes sensitive files such as session data and credentials that can be used to further compromise the device or network.
Description
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.3 to 5.6.7 and 5.4.6 to 5.4.12 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7 under SSL VPN web portal allows an unauthenticated attacker to download system files via special crafted HTTP resource requests.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityThe flaw is unauthenticated, remotely exploitable, has a CVSS score of 9.8, is in CISA KEV with known ransomware use, and has an EPSS probability near 1.0.
What it is
FortiOS and FortiProxy SSL VPN web portals fail to properly restrict pathnames, allowing crafted HTTP requests to traverse directories and download system files. Because the flaw is reachable without authentication, it exposes sensitive files such as session data and credentials that can be used to further compromise the device or network.
Impact
An unauthenticated attacker can read arbitrary system files from the SSL VPN appliance, including files that may contain credentials or session information. This can lead to full compromise of the VPN gateway and lateral movement into protected networks.
Attack surface
The vulnerability is reached over the network through the SSL VPN web portal via specially crafted HTTP resource requests. No authentication or user interaction is required, as reflected by the CVSS vector AV:N/AC:L/PR:N/UI:N.
Exploitation
CVE-2018-13379 is listed in CISA's Known Exploited Vulnerabilities catalog with known ransomware campaign use, and EPSS indicates a near-certain probability of exploitation activity. Vendor advisories and a US Government resource are referenced, confirming active exploitation in the wild.
What to do
- Apply the Fortinet updates specified in FG-IR-18-384 and FG-IR-20-233 for all affected FortiOS and FortiProxy versions.
- If immediate patching is not possible, disable the SSL VPN web portal or restrict access to trusted sources until updates can be applied.
- Rotate credentials and invalidate sessions for any SSL VPN users or administrators who may have been exposed.
- Monitor Fortinet advisories and CISA guidance for additional mitigations or indicators of compromise.
Detection
- Inspect HTTP requests to the SSL VPN web portal for path traversal sequences such as ../ or encoded variants in resource parameters.
- Review web server and SSL VPN logs for anomalous requests to system file paths or unexpected file download activity.
- Monitor for post-exploitation behavior such as creation of new administrative accounts, unusual VPN logins, or outbound connections from the appliance.
- Use network detection to identify known exploitation patterns against Fortinet SSL VPN endpoints.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2018-13379 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Fortinet FortiOS SSL VPN Path Traversal Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.
Ransomware crews whose documented playbooks reference this CVE: