Vulnerability record · CVE-2018-13383 · published 29 May 2019
CVE-2018-13383: Fortinet FortiOS and FortiProxy SSL VPN heap buffer overflow
Fortinet · Fortiproxy
A heap buffer overflow exists in the SSL VPN web portal of Fortinet FortiOS and FortiProxy when proxying webpages, caused by improper handling of javascript href data. It can terminate the SSL VPN web service for logged-in users, and the out-of-bounds write class means memory corruption beyond a simple crash cannot be ruled out.
Description
A heap buffer overflow in Fortinet FortiOS 6.0.0 through 6.0.4, 5.6.0 through 5.6.10, 5.4.0 through 5.4.12, 5.2.14 and earlier and FortiProxy 2.0.0, 1.2.8 and earlier in the SSL VPN web portal may cause the SSL VPN web service termination for logged in users due to a failure to properly handle javascript href data when proxying webpages.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Automated analysis
high priorityThe flaw is a remotely reachable out-of-bounds write in an internet-facing SSL VPN portal, is in CISA KEV with known ransomware use, and has high EPSS, though the stated impact is limited to availability.
What it is
A heap buffer overflow exists in the SSL VPN web portal of Fortinet FortiOS and FortiProxy when proxying webpages, caused by improper handling of javascript href data. It can terminate the SSL VPN web service for logged-in users, and the out-of-bounds write class means memory corruption beyond a simple crash cannot be ruled out.
Impact
An attacker can disrupt the SSL VPN web service for authenticated users, causing denial of service. The CVSS vector scores only availability impact, so no confidentiality or integrity gain is stated in the record.
Attack surface
Reachable over the network through the SSL VPN web portal, with no privileges required but user interaction needed per the CVSS vector (UI:R). The flaw triggers when the portal proxies crafted webpage content containing javascript href data.
Exploitation
Listed in CISA KEV since 2022-01-10 with known ransomware campaign use, and EPSS 30-day probability is about 0.336 (98th percentile), indicating observed exploitation. No public exploit references are included in the record.
What to do
- Apply the Fortinet updates referenced in advisories FG-IR-18-388 and FG-IR-20-229 for FortiOS and FortiProxy.
- If immediate patching is not possible, restrict or disable SSL VPN web portal access and limit exposure of the portal to trusted networks.
- Monitor Fortinet guidance for any interim workarounds and apply them to affected SSL VPN deployments.
- Verify which FortiOS and FortiProxy versions are in use and confirm they fall outside the affected ranges before considering the system remediated.
Detection
- Monitor SSL VPN web portal logs for service termination or crash events affecting logged-in users.
- Alert on abnormal process restarts or crashes of the SSL VPN web service on FortiGate and FortiProxy devices.
- Review web portal proxy traffic for crafted javascript href content and correlate with subsequent service failures.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2018-13383 to the Known Exploited Vulnerabilities catalog on 10 January 2022 as "Fortinet FortiOS and FortiProxy Out-of-bounds Write". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 10 July 2022.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://fortiguard.com/advisory/FG-IR-18-388 | MitigationVendor Advisory |
| https://fortiguard.com/advisory/FG-IR-20-229 | Vendor Advisory |
| https://fortiguard.com/advisory/FG-IR-18-388 | MitigationVendor Advisory |
| https://fortiguard.com/advisory/FG-IR-20-229 | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-13383 | US Government Resource |
Track CVE-2018-13383 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-13383), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.