CVE-2018-13379
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.3 to 5.6.7 and 5.4.6 to 5.4.12 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 ...
Affects 2 products across 1 vendor.
Attacker manipulates file path inputs to access files outside the intended directory.
Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.
CVE-2018-13379 affects Fortinet FortiOS and FortiProxy versions, allowing unauthenticated attackers to perform path traversal attacks and download system files via specially crafted HTTP requests. This vulnerability has a high CVSS score of 9.8 and is listed in the KEV catalog with public proof-of-concept (PoC) and exploits available, making it highly critical for immediate remediation.
BSID: BS-2019-GLOBAL-209902-C • Model: Qwen/Qwen2.5-72B-Instruct-AWQ • Confidence: HIGH
Is this CVE in your environment?
BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.
Check My Environment →What is CVE-2018-13379?
What is the CVSS score for CVE-2018-13379?
Is CVE-2018-13379 actively exploited?
How do I remediate CVE-2018-13379?
What systems are affected by CVE-2018-13379?
What NERC-CIP standard applies to CVE-2018-13379?
What IEC 62443 requirement maps to CVE-2018-13379?
| CVE ID | CVE-2018-13379 |
|---|---|
| BSID | BS-2019-GLOBAL-209902-C BreachSpider Global ID |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| Published | 2019-06-04 |
| Last Modified | 2025-10-24 |
| ICS Relevance | 70% |
| Weakness (CWE) | |
| Domains | |
| Source | NVD |
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.3 to 5.6.7 and 5.4.6 to 5.4.12 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7 under SSL VPN web portal allows an unauthenticated attacker to download system files via special crafted HTTP resource requests.
Source: NIST NVD / MITRE CVE Database
The vulnerability arises from improper limitation of pathname to restricted directories in the SSL VPN web portal. An unauthenticated attacker can exploit this by sending specially crafted HTTP resource requests, leading to the ability to download sensitive system files. This can result in unauthorized access to configuration files, logs, and other critical data, potentially leading to further compromise of the network.
Exploitation Likelihood: CRITICAL
| CISA KEV | ● Active Exploitation Confirmed (added 2021-11-03) |
|---|---|
| Public Exploit | ⚠ Available — Reference |
| PoC Code | Not confirmed |
Implement strict input validation and sanitization on the SSL VPN web portal to prevent path traversal attacks. Additionally, configure the firewall to block suspicious HTTP requests that attempt to access restricted directories.
No reliable network detection signature exists for this vulnerability class — apply the compensating controls above and the vendor patch. SAGE only publishes a network rule when a concrete on-the-wire signature can be grounded in the advisory.
This CVE violates CIP-007-R2 as it allows unauthorized access to system files, which can compromise the security and integrity of the control system environment.
This CVE maps to SR 7.6 because it involves a vulnerability that can be exploited to gain unauthorized access to system files, which is a critical security concern in ICS environments.
Virtual patch generated by CITED Relevance SAGE. Validate in isolated environment before production deployment. Compensating control only - does not replace vendor patch.
SAGE Enrichment Record — provenance & audit hash
| Model | Qwen/Qwen2.5-72B-Instruct-AWQ |
|---|---|
| Confidence | HIGH |
| Enriched At | 2026-05-24 |
| SHA-512 Audit Hash | fffdd72cd49da8fa0ed1b8bd2bcf5a01f87543142ad60751b1fcb8cbcee9f99340ec039a34d98a0a1195a12b005cf90121bce3e32c7358589786aacca53fc8d1 |
This Vulnerability Is Being Actively Exploited
CVE-2018-13379 is on the CISA KEV list - confirmed active exploitation in the wild. BreachSpider alerts your team within 15 minutes when KEV vulnerabilities match your ICS assets.
Start Free KEV Monitoring →