An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.3 to 5.6.7 and 5.4.6 to 5.4.12 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7 under SSL VPN web portal allows an unauthenticated attacker to download system files via special crafted HTTP resource requests.
Is CVE-2018-13379 exploited?
Listed in the CISA KEV catalog on 2021-11-03.
Federal remediation due 2022-05-03.
Past that date by 1565 days.
Used in ransomware campaigns.
EPSS puts exploitation in the next 30 days at 100.0%.