CVE-2018-13381

MEDIUM

FortiProxy <= 1.2.8 and FortiOS < 5.2.14 - Unauthenticated Denial of Service via SSL VPN Web Portal

Title source: llm
STIX 2.1

Description

A buffer overflow vulnerability in Fortinet FortiOS 6.0.0 through 6.0.4, 5.6.0 through 5.6.7, 5.4 and earlier versions and FortiProxy 2.0.0, 1.2.8 and earlier versions under SSL VPN web portal allows a non-authenticated attacker to perform a Denial-of-service attack via special craft message payloads.

References (2)

Core 2
Core References
Mitigation, Vendor Advisory x_refsource_confirm
https://fortiguard.com/advisory/FG-IR-18-387
Vendor Advisory x_refsource_confirm
https://fortiguard.com/advisory/FG-IR-20-232

Scores

CVSS v3 5.3
EPSS 0.0053
EPSS Percentile 67.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-119
Status published
Products (3)
fortinet/fortios < 5.2.14
fortinet/fortiproxy 2.0.0
fortinet/fortiproxy < 1.2.8
Published Jun 04, 2019
Tracked Since Feb 18, 2026