CyberRota Analysis
AI analysis pending.
CISA KEV Details
Status: This CVE is listed in CISA's Known Exploited Vulnerabilities catalog.
Ransomware use: Known
Added to KEV: 2022-01-10
Required action: Apply updates per vendor instructions.
CVE
CVE-2018-13382
Severity
CRITICAL
CVSS
9.1
EPSS
81.69%
Fortinet FortiOS
Original NVD Description
An Improper Authorization vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8 and 5.4.1 to 5.4.10 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7 under SSL VPN web portal allows an unauthenticated attacker to modify the password of an SSL VPN web portal user via specially crafted HTTP requests