S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 8, 2024

CVE-2018-13379 Scanner

CVE-2018-13379 scanner - Path Traversal vulnerability in Fortinet FortiOS, FortiProxy

Est. Time~15 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.3k
Times Used
continuous scan runs
4.2k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2018-13379
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.3 to 5.6.7 and 5.4.6 to 5.4.12 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7 under SSL VPN web portal allows an unauthenticated attacker to download system files via special crafted HTTP resource requests.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Fortinet FortiOS, FortiProxyby Fortinet
FortiOS 6.0.0 to 6.0.4, 5.6.3 to 5.6.7 and 5.4.6 to 5.4.12, FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7
Updated Aug 21, 2026View on NVD →
Detail

Fortinet FortiOS and FortiProxy are security products that are designed to provide protection for digital assets by securing network infrastructures, endpoints, applications, and clouds. Fortinet FortiOS is a powerful operating system that runs on FortiGate network security appliances, allowing customers to stay ahead of the evolving threat landscape while simplifying their overall security posture. FortiProxy, on the other hand, is a web proxy appliance that provides a secure web gateway for protecting users from threats on the internet.

The CVE-2018-13379 vulnerability is a critical security flaw that was detected in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.3 to 5.6.7, and 5.4.6 to 5.4.12, as well as FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6, and 1.0.0 to 1.0.7. This vulnerability, also known as "Path Traversal," occurs when a system fails to limit a pathname, allowing unauthenticated attackers to download system files via specially crafted HTTP resource requests.

If the CVE-2018-13379 vulnerability is exploited, it can lead to a significant data breach and the loss of sensitive information. Attackers can gain access to confidential data, such as user login credentials, financial records, and intellectual property. This vulnerability can also lead to the installation of malicious software that can cause system crashes, infrastructure failures, and other serious consequences.

s4e.io offers a platform with pro features that makes it easy and quick to learn about vulnerabilities in your digital assets. By signing up for this platform, you can receive comprehensive reports on the vulnerabilities present in your digital assets and get actionable and timely advice on how to fix them. With s4e.io, you can rest assured that your digital assets are protected against the latest vulnerabilities and threats.

 

REFERENCES

Solution Advice

To protect against the CVE-2018-13379 vulnerability, it is essential to take precautionary measures, such as:

  • Updating Fortinet FortiOS and FortiProxy to the latest version
  • Using strong passwords and two-factor authentication
  • Implementing a strong access control policy
  • Disabling unnecessary services and features
  • Monitoring access logs

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2018-13379 scanner - Path Traversal vulnerability in Fortinet FortiOS, FortiProxy | S4E