CVE-2018-1352

CRITICAL

A format string vulnerability in Fortinet FortiOS 5.6.0 allows attacker to execute unauthorized code or commands via the SSH username variable.

Affects 1 product across 1 vendor.

BCS7.21
CVSS 3.09.8
EPSS1.2%
Percentile67th
PatchPatched
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, impact contained to the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-134: CWE-134
Related Attack Patterns (CAPEC)
CAPEC-67 String Format Overflow in syslog()
via CWE-134
CAPEC-135 Format String Injection
via CWE-134

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ AI Analysis — automated analysis, not human-reviewed

This vulnerability was disclosed in 2019. A critical vulnerability affects Fortinet systems (CVE-2018-1352). No public exploit code is currently available. Isolate affected systems if patching is not feasible.

BSID: BS-2019-GLOBAL-127958-C • Model: rule-based-v1 • Confidence: MEDIUM

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2018-1352?
This vulnerability was disclosed in 2019. A critical vulnerability affects Fortinet systems (CVE-2018-1352). No public exploit code is currently available. Isolate affected systems if patching is not feasible.
What is the CVSS score for CVE-2018-1352?
CVE-2018-1352 has CVSS 9.8 (Critical). Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. EPSS: 1.2%.
Is CVE-2018-1352 actively exploited?
No confirmed active exploitation of CVE-2018-1352 as of 2026-05-30.
How do I remediate CVE-2018-1352?
Priority: MEDIUM. Advisory: https://fortiguard.com/advisory/FG-IR-18-018 PSIRT: [email protected]
What systems are affected by CVE-2018-1352?
CVE-2018-1352 affects: Fortinet.
Vulnerability Details
CVE IDCVE-2018-1352
BSIDBS-2019-GLOBAL-127958-C BreachSpider Global ID
CVSS VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Published2019-02-08
Last Modified2024-11-21
ICS Relevance55%
Weakness (CWE)
Domains
NETWORK-INFRA
SourceNVD
Official Description

A format string vulnerability in Fortinet FortiOS 5.6.0 allows attacker to execute unauthorized code or commands via the SSH username variable.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

Vulnerability details: A format string vulnerability in Fortinet FortiOS 5.6.0 allows attacker to execute unauthorized code or commands via the SSH username variable. CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H.

Exploitation Likelihood: LOW

Affected Products
VendorProductFixed Version
Fortinet Fortios —
Remediation
View Vendor Advisory →

Remediation Priority: MEDIUM

Vendor PSIRT: [email protected]
Threat Intelligence
● Threat Intelligence Validated: September 2026 | Threat Age: 2788 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
AI Enrichment Record — provenance & audit hash
Modelrule-based-v1
ConfidenceMEDIUM
Enriched At2026-05-24
SHA-512 Audit Hashe630a4f00dc8b224f4c7155a05c3a3ecf6f9fdfdf0969b8d6b1adce7f5c6a0f41c69f1c91753592b6a66cebc1c0524178403546416e81d3d6a4a5a8eb908b837
Related CVEs affecting Fortinet
CVE-2005-3057 10.0 The FTP component in FortiGate 2.8 running FortiOS 2.8MR10 and v3beta, and ot... CVE-2017-7336 9.8 A hard-coded account named 'upgrade' in Fortinet FortiWLM 8.3.0 and lower ver... CVE-2016-4573 9.8 Fortinet FortiSwitch FSW-108D-POE, FSW-124D, FSW-124D-POE, FSW-224D-POE, FSW-... CVE-2015-3616 9.8 SQL injection vulnerability in Fortinet FortiManager 5.0.x before 5.0.11, 5.2... CVE-2017-17540 9.8 The presence of a hardcoded account in Fortinet FortiWLC 8.3.3 allows attacke...
View all Fortinet CVEs →

Critical Severity - Know Your Exposure

A CVSS 9.8 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Create a free account →