Skip to content

FortiOS SSL VPN (CVE-2018-13379)

CVE-2018-13379CWE-22OWASP A01:2021CVSS 9.1Updated October 1, 20262 min read

CVE-2018-13379 is a path traversal in the FortiOS SSL VPN that let an unauthenticated attacker request a session file containing usernames and passwords in plain text. The patch shipped in 2019, but lists of harvested credentials still circulate years later and unpatched appliances are still being found.

Affected
FortiOS 5.4.6 to 5.4.12, 5.6.3 to 5.6.7 and 6.0.0 to 6.0.4, and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6 and 1.0.0 to 1.0.7, with SSL VPN enabled
Patched in
FortiOS 5.4.13, 5.6.8, 6.0.5 and 6.2.0 or later; FortiProxy 1.2.9 and 2.0.1 or later
Actively exploited
yes

Of every vulnerability in this overview this is the oldest, and for that reason the most instructive. The patch has existed since 2019. Yet CVE-2018-13379 turns up year after year in lists of the most routinely exploited vulnerabilities.

What is CVE-2018-13379

The FortiOS SSL VPN portal accepted a filename in the URL without checking that it stayed inside the intended directory. With a sequence of ../ an attacker could break out of that directory and request arbitrary files. That is a classic path traversal. The same flaw was present in the SSL VPN portal of FortiProxy, Fortinet’s web proxy.

The file that mattered is called sslvpn_websession. In it the appliance stored the details of active sessions, usernames and passwords in plain text included.

Fortinet scores the flaw 9.1. NVD rates it 9.8 because it also counts an impact on integrity.

Why this flaw has such a long tail

An ordinary vulnerability disappears with the patch. This one does not. After a single request the attacker no longer needed a vulnerability: they had working credentials. In November 2020 a list of credentials from tens of thousands of Fortinet VPNs was published. Organisations that patched shortly after but left their passwords unchanged remained reachable through the front door.

Who uses it

Both ransomware affiliates and state-linked actors have deployed this flaw, and Western security agencies warned about it repeatedly. The reason is prosaic: it costs no effort, vulnerable appliances still exist, and the payoff is direct VPN access to the internal network.

What to do now

  • Check which FortiOS build your VPN runs. Every branch named in the advisory, 5.4 up to and including 6.2, is end-of-life. Move to a branch Fortinet still supports, such as 7.4 or 7.6, and keep it on the latest patch release. The same goes for FortiProxy: run a release line that is still supported.
  • Reset the passwords of every VPN user if the appliance was ever internet-facing while vulnerable.
  • Put multi-factor authentication on every form of remote access. It is the one control that makes a leaked password worthless.
  • Review the VPN logs for sign-ins from unusual locations or outside working hours.

Sources

Frequently asked questions

Why does a 2018 flaw still appear in lists from 2024?

Because the harvested credentials do not expire when the appliance is patched. An organisation that leaked a password in 2020 and never changed it is still exposed today.

What should I do if we were exposed back then?

Patching is step one, but every VPN user password has to be reset and multi-factor authentication has to go on. Otherwise the leaked list stays usable.

How do I know whether our credentials are on such a list?

You rarely can establish that with certainty. Assume they are if the appliance was internet-facing and unpatched at the time.

Related articles

Press / to search · Esc