← KEV catalog
CISA known exploited vulnerability

CVE-2018-13382

Fortinet FortiOS and FortiProxy Improper Authorization

SOURCE FACT

Fortinet · FortiOS and FortiProxy

An Improper Authorization vulnerability in Fortinet FortiOS and FortiProxy under SSL VPN web portal allows an unauthenticated attacker to modify the password.

Required action

Apply updates per vendor instructions.

CISA notes

https://nvd.nist.gov/vuln/detail/CVE-2018-13382

View source evidence →

CHECK YOUR OUTSIDE-IN INVENTORY

Could this product be present?