CVE-2018-13381: Buffer Overflow
A buffer overflow vulnerability in Fortinet FortiOS 6.0.0 through 6.0.4, 5.6.0 through 5.6.7, 5.4 and earlier versions and FortiProxy 2.0.0, 1.2.8 and earlier versions under SSL VPN web portal allows a non-authenticated attacker to perform a Denial-of-service attack via special craft message payloads.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-13381?
CVE-2018-13381 is a buffer overflow vulnerability in Fortinet FortiOS and FortiProxy that allows a non-authenticated attacker to perform a Denial-of-Service attack.
Which versions of Fortinet FortiOS are affected by CVE-2018-13381?
Fortinet FortiOS versions 6.0.0 through 6.0.4, 5.6.0 through 5.6.7, and 5.4 and earlier versions are affected by CVE-2018-13381.
Which version of Fortinet FortiProxy is affected by CVE-2018-13381?
Fortinet FortiProxy version 2.0.0 and 1.2.8 are affected by CVE-2018-13381.
What is the severity of CVE-2018-13381?
CVE-2018-13381 has a severity rating of 7.5 (high).
How can I mitigate the vulnerability CVE-2018-13381?
To mitigate the vulnerability CVE-2018-13381, it is recommended to update to the latest patched version of Fortinet FortiOS and FortiProxy.