CVE-2018-13366: Infoleak
Published Apr 9, 2019
·Updated
An information disclosure vulnerability in Fortinet FortiOS 6.0.1, 5.6.7 and below allows attacker to reveals serial number of FortiGate via hostname field defined in connection control setup packets of PPTP protocol.
Affected Software
3 affected components
Fortinet FortiOS<=5.6.7
Fortinet FortiOS=6.0.0
Fortinet FortiOS=6.0.1
Event History
Apr 9, 2019
CVE Published
via MITRE·04:20 PM
Data Sourced
via MITRE·04:20 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-13366?
CVE-2018-13366 is classified as a medium severity information disclosure vulnerability.
2
How do I fix CVE-2018-13366?
To mitigate CVE-2018-13366, upgrade Fortinet FortiOS to version 6.0.2 or above, or 5.6.8 or above.
3
What does CVE-2018-13366 expose?
CVE-2018-13366 allows an attacker to disclose the serial number of FortiGate devices through the hostname field in PPTP protocol packets.
4
Which versions of FortiOS are affected by CVE-2018-13366?
FortiOS versions 6.0.1, 6.0.0, and 5.6.7 and below are affected by CVE-2018-13366.
5
Is the CVE-2018-13366 vulnerability related to FortiGate devices' security?
Yes, CVE-2018-13366 directly impacts the security of FortiGate devices by revealing sensitive information.