Fortigate SSL VPN Arbitrary File reading (CVE-2018-13379)

Severity: High
Summary#

Invicti detected Fortigate SSL VPN Arbitrary File reading (CVE-2018-13379)

A directory traversal vulnerability exists on Fortigate SSL VPN. An attacker can craft a request that accesses potentially sensitive information in the Fortigate's filesystem.
Impact#
An attacker could exploit this vulnerability to gain unauthorized read access to sensitive files including users VPN credentials.
Remediation#

Upgrade to the latest version of FortiOS

Build your resistance to threats. And save hundreds of hours each month.

Get a demo See how it works