Vulnerability record · CVE-2018-13382 · published 4 June 2019
CVE-2018-13382: Fortinet FortiOS and FortiProxy SSL VPN web portal improper authorization
Fortinet · Fortiproxy
FortiOS and FortiProxy SSL VPN web portals contain an improper authorization flaw (CWE-863) that lets an unauthenticated attacker change the password of an SSL VPN web portal user through crafted HTTP requests. Because the portal is internet-facing and no credentials are required, the flaw exposes remote access accounts to takeover.
Description
An Improper Authorization vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8 and 5.4.1 to 5.4.10 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7 under SSL VPN web portal allows an unauthenticated attacker to modify the password of an SSL VPN web portal user via specially crafted HTTP requests
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Automated analysis
critical priorityIt is in CISA KEV with known ransomware use, has a very high EPSS score, and allows unauthenticated remote password changes on internet-facing SSL VPN portals.
What it is
FortiOS and FortiProxy SSL VPN web portals contain an improper authorization flaw (CWE-863) that lets an unauthenticated attacker change the password of an SSL VPN web portal user through crafted HTTP requests. Because the portal is internet-facing and no credentials are required, the flaw exposes remote access accounts to takeover.
Impact
An attacker can reset a portal user's password without authentication, potentially taking over that account and gaining SSL VPN access. The CVSS vector shows high integrity impact with no confidentiality or availability impact.
Attack surface
Reachable over the network through the SSL VPN web portal via specially crafted HTTP requests. No authentication or user interaction is required per the CVSS vector (PR:N/UI:N).
Exploitation
CISA added this to the Known Exploited Vulnerabilities catalog on 2022-01-10 with known ransomware campaign use, and EPSS is 0.81691 (99.6th percentile), indicating active exploitation.
What to do
- Apply the Fortinet updates referenced in FG-IR-18-389 and FG-IR-20-231 for affected FortiOS and FortiProxy versions.
- If immediate patching is not possible, restrict or disable SSL VPN web portal access from untrusted networks.
- Enforce multi-factor authentication on SSL VPN accounts and monitor for unexpected password changes.
- Review SSL VPN portal user accounts for unauthorized password resets and rotate credentials where compromise is suspected.
Detection
- Monitor SSL VPN web portal logs for password-change requests from unauthenticated or unexpected source IPs.
- Alert on HTTP requests to SSL VPN portal password-change endpoints that lack a valid authenticated session.
- Correlate portal password-change events with subsequent successful SSL VPN logins from new or anomalous locations.
- Hunt for known exploitation patterns against FortiOS/FortiProxy SSL VPN portals using network and web logs.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2018-13382 to the Known Exploited Vulnerabilities catalog on 10 January 2022 as "Fortinet FortiOS and FortiProxy Improper Authorization". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 10 July 2022.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://fortiguard.com/advisory/FG-IR-18-389 | Vendor Advisory |
| https://www.fortiguard.com/psirt/FG-IR-20-231 | Vendor Advisory |
| https://fortiguard.com/advisory/FG-IR-18-389 | Vendor Advisory |
| https://www.fortiguard.com/psirt/FG-IR-20-231 | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-13382 | US Government Resource |
Track CVE-2018-13382 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-13382), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.