CVE-2018-13382

CVE Published 2019-06-04
Related CWE(s) CWE-863: Incorrect Authorization, CWE-285: Improper Authorization
Related Vendor(s) fortinet
Related Product(s) fortiproxy, fortios
Exploitation Reported (CISA KEV) 2022-01-10
CVSS 3 Base Score 9.1 (CRITICAL)
CVSS 3 Attack Complexity LOW
CVSS 3 Attack Vector NETWORK

An Improper Authorization vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8 and 5.4.1 to 5.4.10 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7 under SSL VPN web portal allows an unauthenticated attacker to modify the password of an SSL VPN web portal user via specially crafted HTTP requests

Cyber Threat Graph Context

Explore how this CVE relates to the wider threat graph

Associated CAPEC Patterns

References