#VU31052 Buffer overflow in FortiOS - CVE-2018-13383
Published: May 29, 2019 / Updated: February 20, 2022
FortiOS
Fortinet, Inc
Description
The vulnerability allows a remote non-authenticated attacker to compromise the affected system.
The vulnerability exists due to a boundary error when parsing web pages in the SSL VPN web portal. A remote attacker can create a specially crafted web page with malicious javascript href data, trick the authenticated user to visit it, trigger a buffer overflow and execute arbitrary code on the system.