Home / Early Warning / Vulnerabilidades / CVE-2018-13379

CVE-2018-13379

Type: 
Path Traversal
Severity: 
Medium
Publication date: 
06/04/2019
Last modified: 
09/19/2019
Description
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.3 to 5.6.7 under SSL VPN web portal allows an unauthenticated attacker to download system files via special crafted HTTP resource requests.
Impact
Access Vector: Through network
Access Complexity: Low
Authentication: Not required to exploit
Impact Type: No impact on system integrity + Partially affects on system confidentiality + No impact on system availability
Vulnerable software and versions
  • cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*
To consult the complete list of products and versions see this page
Explanation of fields