Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2018-13379 — AI Deep Analysis Summary

CVSS 9.1 · Critical

Q1What is this vulnerability? (Essence + Consequences)

🚨 **Essence**: A **Path Traversal** flaw in FortiOS SSL VPN Web Portal. 📂 💥 **Consequences**: Attackers can access files **outside** restricted directories. Critical system files can be downloaded. 🔓

Q2Root Cause? (CWE/Flaw)

🛡️ **Root Cause**: **Improper Limitation of a Pathname** to a Restricted Directory. 🚫 🔍 **Flaw**: The system fails to filter special elements in resource/file paths correctly. ❌

Q3Who is affected? (Versions/Components)

🏢 **Vendor**: Fortinet (FortiOS & FortiProxy). 📦 📅 **Affected Versions**: • 5.6.3 to 5.6.7 • 6.0.0 to 6.0.4 ⚠️ **Condition**: SSL VPN service (web/tunnel mode) must be enabled. 🔌

Q4What can hackers do? (Privileges/Data)

🕵️ **Attacker Action**: Unauthenticated download of **system files**. 💾 🔑 **Privileges/Data**: High impact on Confidentiality (C:H) and Availability (A:H). No integrity loss (I:N). 📉

Q5Is exploitation threshold high? (Auth/Config)

🔓 **Threshold**: **LOW**. 📉 🚫 **Auth**: **Unauthenticated** (PR:N). No login needed. 🔑 🌐 **Access**: Network accessible (AV:N). 🌍

Q6Is there a public Exp? (PoC/Wild Exploitation)

💣 **Public Exp**: **YES**. 🧨 🔗 **PoCs**: Multiple GitHub repos (milo2012, 0xHunter, etc.). 🐙 🛠️ **Tools**: Nmap scripts, Router Scan modules, Python exploits available. 🛠️

Q7How to self-check? (Features/Scanning)

🔍 **Self-Check**: • Use **Nmap NSE scripts** for detection. 📡 • Scan via **Project Sonar** data (Tor). 🌐 • Check for specific HTTP resource request responses. 📡

Q8Is it fixed officially? (Patch/Mitigation)

🩹 **Official Fix**: **YES**. 🛡️ 📜 **Advisory**: FortiGuard PSIRT FG-IR-18-384 & FG-IR-20-233. 📄 ✅ **Action**: Update to patched versions immediately. 🔄

Q9What if no patch? (Workaround)

🚧 **No Patch?**: • **Disable SSL VPN** if not needed. 🔌 • Restrict access to the SSL VPN web portal via firewall rules. 🚫 • Monitor for unauthorized file access attempts. 👀

Q10Is it urgent? (Priority Suggestion)

🔥 **Urgency**: **HIGH**. 🚨 ⚡ **Priority**: Critical. Unauthenticated + Public Exploit = Immediate Action Required. 🏃‍♂️💨