CISA Known Exploited Vulnerability

CVE-2018-13383 Ransomware

Fortinet · FortiOS and FortiProxy

Fortinet FortiOS and FortiProxy Out-of-bounds Write

Date added
BOD 22-01 due date
CWE CWE-787
Ransomware Known

CISA description

A heap buffer overflow in Fortinet FortiOS and FortiProxy may cause the SSL VPN web service termination for logged in users.

Required action

Apply updates per vendor instructions.