CISA Known Exploited Vulnerability

CVE-2018-13382 Ransomware

Fortinet · FortiOS and FortiProxy

Fortinet FortiOS and FortiProxy Improper Authorization

Date added
BOD 22-01 due date
CWE CWE-285
Ransomware Known

CISA description

An Improper Authorization vulnerability in Fortinet FortiOS and FortiProxy under SSL VPN web portal allows an unauthenticated attacker to modify the password.

Required action

Apply updates per vendor instructions.