CVE-2018-13383: Fortinet FortiOS and FortiProxy Out-of-bounds Write
A heap buffer overflow in Fortinet FortiOS 6.0.0 through 6.0.4, 5.6.0 through 5.6.10, 5.4.0 through 5.4.12, 5.2.14 and earlier and FortiProxy 2.0.0, 1.2.8 and earlier in the SSL VPN web portal may cause the SSL VPN web service termination for logged in users due to a failure to properly handle javascript href data when proxying webpages.
Other sources
A heap buffer overflow in Fortinet FortiOS and FortiProxy may cause the SSL VPN web service termination for logged in users.
— CISA
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this Fortinet vulnerability?
The vulnerability ID for this Fortinet vulnerability is CVE-2018-13383.
What is the severity of CVE-2018-13383?
CVE-2018-13383 has a severity rating of 6.5 (medium).
Which software versions are affected by CVE-2018-13383?
CVE-2018-13383 affects Fortinet FortiOS 6.0.0 through 6.0.4, 5.6.0 through 5.6.10, 5.4.0 through 5.4.12, 5.2.14 and earlier, as well as FortiProxy 2.0.0, 1.2.8 and earlier.
What is the impact of CVE-2018-13383?
CVE-2018-13383 may cause the SSL VPN web service termination for logged in users due to a failure to properly handle javas…
Where can I find more information about CVE-2018-13383?
You can find more information about CVE-2018-13383 on the Fortinet FortiGuard advisory pages: [FG-IR-18-388](https://fortiguard.com/advisory/FG-IR-18-388) and [FG-IR-20-229](https://fortiguard.com/advisory/FG-IR-20-229).