Path traversal in FortiOS - CVE-2018-13379
Published: May 27, 2019 / Updated: November 29, 2024
Vulnerability details
The vulnerability allows a remote attacker to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences. A remote non-authenticated attacker can send a specially crafted HTTP request and download arbitrary file from FortiOS SSL VPN web portal.
Affected software
FortiProxy
How to mitigate CVE-2018-13379
Install updates from vendor's website.
As a temporary solution, disable the SSL-VPN web portal service by applying the following CLI commands:
config vpn ssl settings
unset source-interface
end
FortiProxy - addressed in versions 1.2.9, 2.0.1
Links to Public Exploits and PoC-codes
- Exploit #10923 - CVE-2018-13379 (An exploit for Fortinet CVE-2018-13379) (November 29, 2024)
- Exploit #5893 - FortiOS 5.6.3 - 5.6.7 / FortiOS 6.0.0 - 6.0.4 - Credentials Disclosure (June 17, 2021)
- Exploit #5894 - FortiOS 5.6.3 - 5.6.7 / FortiOS 6.0.0 - 6.0.4 - Credentials Disclosure (Metasploit) (June 17, 2021)
- Exploit #5386 - FortiOS Path Traversal Credential Gatherer (May 9, 2021)
- Exploit #4912 - fortios_vpnssl_traversal_leak (This module massively scan and exploit a path traversal vulnerability in the FortiOS SSL VPN web portal may allow an unauthenticated attacker to download FortiOS system files through specially crafted HTTP resource requests (December 11, 2020)
- Exploit #258 - FortiOS-Credentials-Disclosure (CVE-2018-13379 Exploit) (March 18, 2020)