← Vulnerability feed

Vulnerability record · CVE-2018-13379 · published 4 June 2019

CVE-2018-13379: Fortinet FortiOS and FortiProxy SSL VPN path traversal allows unauthenticated file download

Fortinet · Fortiproxy

FortiOS and FortiProxy SSL VPN web portals fail to properly restrict pathnames, allowing crafted HTTP requests to traverse directories and download system files. Because the flaw is reachable without authentication, it exposes sensitive files such as session data and credentials that can be used to further compromise the device or network.

9.8 CVSS 3.1 Critical CISA KEV since 3 Nov 2021 Known ransomware use EPSS 100% · top 0.1% CWE-22 · Path traversal
9.8CVSS 3.1 base score, v2 5.0
100%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
2Affected product versions listed by NVD
5References
17 Jun 2026Last modified by NVD

Description

An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.3 to 5.6.7 and 5.4.6 to 5.4.12 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7 under SSL VPN web portal allows an unauthenticated attacker to download system files via special crafted HTTP resource requests.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityThe flaw is unauthenticated, remotely exploitable, has a CVSS score of 9.8, is in CISA KEV with known ransomware use, and has an EPSS probability near 1.0.

What it is

FortiOS and FortiProxy SSL VPN web portals fail to properly restrict pathnames, allowing crafted HTTP requests to traverse directories and download system files. Because the flaw is reachable without authentication, it exposes sensitive files such as session data and credentials that can be used to further compromise the device or network.

Impact

An unauthenticated attacker can read arbitrary system files from the SSL VPN appliance, including files that may contain credentials or session information. This can lead to full compromise of the VPN gateway and lateral movement into protected networks.

Attack surface

The vulnerability is reached over the network through the SSL VPN web portal via specially crafted HTTP resource requests. No authentication or user interaction is required, as reflected by the CVSS vector AV:N/AC:L/PR:N/UI:N.

Exploitation

CVE-2018-13379 is listed in CISA's Known Exploited Vulnerabilities catalog with known ransomware campaign use, and EPSS indicates a near-certain probability of exploitation activity. Vendor advisories and a US Government resource are referenced, confirming active exploitation in the wild.

What to do

  • Apply the Fortinet updates specified in FG-IR-18-384 and FG-IR-20-233 for all affected FortiOS and FortiProxy versions.
  • If immediate patching is not possible, disable the SSL VPN web portal or restrict access to trusted sources until updates can be applied.
  • Rotate credentials and invalidate sessions for any SSL VPN users or administrators who may have been exposed.
  • Monitor Fortinet advisories and CISA guidance for additional mitigations or indicators of compromise.

Detection

  • Inspect HTTP requests to the SSL VPN web portal for path traversal sequences such as ../ or encoded variants in resource parameters.
  • Review web server and SSL VPN logs for anomalous requests to system file paths or unexpected file download activity.
  • Monitor for post-exploitation behavior such as creation of new administrative accounts, unusual VPN logins, or outbound connections from the appliance.
  • Use network detection to identify known exploitation patterns against Fortinet SSL VPN endpoints.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2018-13379 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Fortinet FortiOS SSL VPN Path Traversal Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.

Ransomware crews whose documented playbooks reference this CVE: