CVE-2018-13379: FortiOS SSL VPN Path Traversal
A pre-authentication path traversal vulnerability in the FortiOS SSL VPN web portal that lets an unauthenticated attacker read arbitrary system files, including the session file that stores usernames and plaintext passwords of previously authenticated VPN users. Despite being disclosed and patched in 2019, unpatched appliances and leaked credential lists from this flaw were still being exploited by ransomware actors years later.
View the authoritative record on NVD ↗Affected software
- FortiOS 6.0.0 through 6.0.4
- FortiOS 5.6.3 through 5.6.7
- FortiOS 5.4.6 through 5.4.12
How it's exploited
Send a crafted HTTP resource request to the SSL VPN web portal with a path traversal sequence targeting the sslvpn_websession file, which the unpatched portal returns without requiring authentication, disclosing plaintext VPN usernames and passwords.
Severity
CVE-2018-13379 carries a CVSS 3.1 base score of 9.8, rated Critical. See how CVSS scoring works or score a vulnerability yourself with the free CVSS calculator.
Weakness type
CVE-2018-13379 is categorized under CWE-22, the general weakness pattern behind this specific vulnerability.
How TurboPentest tests for this
TurboPentest's automated black-box pentest actively probes for Path Traversal using OWASP ZAP and Nuclei and FFUF, with no source code required. Connecting a GitHub repo adds white-box confirmation from IntegSec's Opengrep SAST rule pack, which carries 9 dedicated rules for this weakness.
Tools: OWASP ZAP, Nuclei, FFUF
Remediation
Upgrade FortiOS to a fixed version and force a password reset for every VPN user, since credential lists harvested through this flaw circulated publicly and were reused long after the patch shipped.
Frequently asked questions
What is CVE-2018-13379?
A pre-authentication path traversal vulnerability in the FortiOS SSL VPN web portal that lets an unauthenticated attacker read arbitrary system files, including the session file that stores usernames and plaintext passwords of previously authenticated VPN users. Despite being disclosed and patched in 2019, unpatched appliances and leaked credential lists from this flaw were still being exploited by ransomware actors years later.
How severe is CVE-2018-13379?
CVE-2018-13379 has a CVSS 3.1 base score of 9.8 out of 10, rated Critical.
What software is affected by CVE-2018-13379?
CVE-2018-13379 affects FortiOS 6.0.0 through 6.0.4; FortiOS 5.6.3 through 5.6.7; FortiOS 5.4.6 through 5.4.12.
How do you fix CVE-2018-13379?
Upgrade FortiOS to a fixed version and force a password reset for every VPN user, since credential lists harvested through this flaw circulated publicly and were reused long after the patch shipped.
Where is the authoritative record for CVE-2018-13379?
The National Vulnerability Database (NVD) publishes the authoritative record for CVE-2018-13379 at https://nvd.nist.gov/vuln/detail/CVE-2018-13379, including the current CVSS score, CWE mapping, and affected-configuration data.
Related CVEs
About this reference
These security references are maintained by IntegSec, an offensive-security firm whose team holds CISSP, OSCP, and OSCE certifications and has run thousands of penetration tests. Content is kept current as tools, standards, and attack techniques evolve.
Find known-vulnerable services before an attacker does
TurboPentest fingerprints every open port and web service, then matches detected versions against known CVEs automatically, from $99 per target.
Start a pentest