CVE-2018-13379

● KEV CRITICAL ⚠ Exploit

An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.3 to 5.6.7 and 5.4.6 to 5.4.12 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 ...

Affects 2 products across 1 vendor.

BCS10.0
CVSS 3.19.8
EPSS100.0%
Percentile100th
PatchPatched
KEV Added2021-11-03
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, impact contained to the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-22: Path Traversal

Attacker manipulates file path inputs to access files outside the intended directory.

Related Attack Patterns (CAPEC)
CAPEC-64 Using Slashes and URL Encoding Combined to Bypass Validation Logic
via CWE-22
CAPEC-76 Manipulating Web Input to File System Calls
via CWE-22
CAPEC-78 Using Escaped Slashes in Alternate Encoding
via CWE-22
CAPEC-79 Using Slashes in Alternate Encoding
via CWE-22
CAPEC-126 Path Traversal
via CWE-22

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

CVE-2018-13379 affects Fortinet FortiOS and FortiProxy versions, allowing unauthenticated attackers to perform path traversal attacks and download system files via specially crafted HTTP requests. This vulnerability has a high CVSS score of 9.8 and is listed in the KEV catalog with public proof-of-concept (PoC) and exploits available, making it highly critical for immediate remediation.

BSID: BS-2019-GLOBAL-209902-C • Model: Qwen/Qwen2.5-72B-Instruct-AWQ • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2018-13379?
CVE-2018-13379 affects Fortinet FortiOS and FortiProxy versions, allowing unauthenticated attackers to perform path traversal attacks and download system files via specially crafted HTTP requests. This vulnerability has a high CVSS score of 9.8 and is listed in the KEV catalog with public proof-of-concept (PoC) and exploits available, making it highly critical for immediate remediation.
What is the CVSS score for CVE-2018-13379?
CVE-2018-13379 has CVSS 9.8 (Critical). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. EPSS: 100.0%.
Is CVE-2018-13379 actively exploited?
Yes. CVE-2018-13379 is in the CISA KEV catalog (added 2021-11-03). Active exploitation confirmed. Immediate patching required.
How do I remediate CVE-2018-13379?
Priority: IMMEDIATE. Advisory: https://fortiguard.com/advisory/FG-IR-18-384 PSIRT: [email protected]
What systems are affected by CVE-2018-13379?
CVE-2018-13379 affects: Fortinet, Fortinet.
What NERC-CIP standard applies to CVE-2018-13379?
NERC CIP CIP-007 CIP-007-R2: This CVE violates CIP-007-R2 as it allows unauthorized access to system files, which can compromise the security and integrity of the control system environment.
What IEC 62443 requirement maps to CVE-2018-13379?
IEC 62443 SR 7.6: This CVE maps to SR 7.6 because it involves a vulnerability that can be exploited to gain unauthorized access to system files, which is a critical security concern in ICS environments.
Vulnerability Details
CVE IDCVE-2018-13379
BSIDBS-2019-GLOBAL-209902-C BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Published2019-06-04
Last Modified2025-10-24
ICS Relevance70%
Weakness (CWE)
Domains
NETWORK-INFRA
SourceNVD
Official Description

An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.3 to 5.6.7 and 5.4.6 to 5.4.12 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7 under SSL VPN web portal allows an unauthenticated attacker to download system files via special crafted HTTP resource requests.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

The vulnerability arises from improper limitation of pathname to restricted directories in the SSL VPN web portal. An unauthenticated attacker can exploit this by sending specially crafted HTTP resource requests, leading to the ability to download sensitive system files. This can result in unauthorized access to configuration files, logs, and other critical data, potentially leading to further compromise of the network.

Exploitation Likelihood: CRITICAL

Affected Products
VendorProductFixed Version
Fortinet Fortios
Fortinet Fortiproxy
Remediation
View Vendor Advisory →

Remediation Priority: IMMEDIATE

Vendor PSIRT: [email protected]
Threat Intelligence
● Threat Intelligence Validated: August 2026 | Threat Age: 2633 Days
CISA KEV● Active Exploitation Confirmed (added 2021-11-03)
Public Exploit⚠ AvailableReference
PoC CodeNot confirmed
● Virtual Patch — CITED Relevance SAGE Engine MEDIUM CONFIDENCE

Implement strict input validation and sanitization on the SSL VPN web portal to prevent path traversal attacks. Additionally, configure the firewall to block suspicious HTTP requests that attempt to access restricted directories.

No reliable network detection signature exists for this vulnerability class — apply the compensating controls above and the vendor patch. SAGE only publishes a network rule when a concrete on-the-wire signature can be grounded in the advisory.

NERC CIP: CIP-007 CIP-007-R2
This CVE violates CIP-007-R2 as it allows unauthorized access to system files, which can compromise the security and integrity of the control system environment.
IEC 62443: SR 7.6
This CVE maps to SR 7.6 because it involves a vulnerability that can be exploited to gain unauthorized access to system files, which is a critical security concern in ICS environments.

Virtual patch generated by CITED Relevance SAGE. Validate in isolated environment before production deployment. Compensating control only - does not replace vendor patch.

SAGE Enrichment Record — provenance & audit hash
ModelQwen/Qwen2.5-72B-Instruct-AWQ
ConfidenceHIGH
Enriched At2026-05-24
SHA-512 Audit Hashfffdd72cd49da8fa0ed1b8bd2bcf5a01f87543142ad60751b1fcb8cbcee9f99340ec039a34d98a0a1195a12b005cf90121bce3e32c7358589786aacca53fc8d1
Related CVEs affecting Fortinet
CVE-2005-3057 10.0 The FTP component in FortiGate 2.8 running FortiOS 2.8MR10 and v3beta, and ot... CVE-2024-47575 9.8 A missing authentication for critical function in FortiManager 7.6.0, FortiMa... CVE-2025-25249 9.8 A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through ... CVE-2023-47539 9.8 An improper access control vulnerability in FortiMail version 7.4.0 configure... CVE-2026-24858 9.8 An Authentication Bypass Using an Alternate Path or Channel vulnerability [CW...
View all Fortinet CVEs →

This Vulnerability Is Being Actively Exploited

CVE-2018-13379 is on the CISA KEV list - confirmed active exploitation in the wild. BreachSpider alerts your team within 15 minutes when KEV vulnerabilities match your ICS assets.

Start Free KEV Monitoring →