CVE-2018-13382Fortinet FortiOS and FortiProxy Improper Authorization

PUBLISHEDvulnerability record
2022-01-10 · last modified June 21, 2025

Metadata

CVE ID:
CVE-2018-13382
Project:
Fortinet
Product:
FortiOS and FortiProxy
Date Added:
2022-01-10
Due Date:
2022-07-10
Last Updated:
June 21, 2025

Vulnerability Name

Fortinet FortiOS and FortiProxy Improper Authorization

Description

An Improper Authorization vulnerability in Fortinet FortiOS and FortiProxy under SSL VPN web portal allows an unauthenticated attacker to modify the password.

Known To Be Used in Ransomware Campaigns?

Ransomware Status:
KNOWN

Action

Apply updates per vendor instructions.

Additional Notes

Related Weaknesses