An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.3 to 5.6.7 and 5.4.6 to 5.4.12 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7 under SSL VPN web portal allows an unauthenticated attacker to download system files via special crafted HTTP resource requests.
AI-assisted analytical recommendationDoes not set factual exploitation state
AI review stateREVIEWED
AI priorityNONE
AI confidence85%
Public exploitation · VTP factKEV
Assessment
CVE-2018-13379 lets an unauthenticated attacker use crafted SSL VPN portal requests to download restricted system files. CISA KEV lists known exploitation and known ransomware campaign use.
Why it matters
SSL VPN portals are remotely reachable access services.
Downloaded system files can expose credentials or configuration information for follow-on access.
Evidence
0 record references and 0 source references passed trusted post-response validation. The current deterministic record contains 0 independent evidence groups.
Uncertainties
Recent Fortinet reporting in this bundle does not identify CVE-2018-13379.
First-party honeypot request semantics are potentially consistent with this CVE. This is an unconfirmed candidate match, not proof of exploitation or successful execution.
Next watchpoint
If you use affected FortiOS or FortiProxy SSL VPN versions, upgrade to a fixed release and rotate exposed credentials.
AI baseline history (2)
BASELINE ASSESSED
FortiOS and FortiProxy SSL VPN path traversalgpt-5.6-terra · low
Exploit maturityTECHNICAL DETAILSReliability not implied
EPSS1.00100th percentile · prediction
Evidence confidence64%Strongest independent active claim
VelocitySTABLEMaterial events only
First-party telemetryFirst-party honeypot request semantics are potentially consistent with this CVE. This is an unconfirmed candidate match, not proof of exploitation or successful execution.
CISA KEV lists this vulnerability as known to be exploited globally.
02
EPSS is 1.00; this is predictive context, not exploitation evidence.
03
Exploitation attempts against this CVE were confirmed by first-party telemetry.
04
First-party honeypot request semantics are potentially consistent with this CVE. This is an unconfirmed candidate match, not proof of exploitation or successful execution.
02
Material change ledger
What changed
KEV ADDEDCISA KEV entry added
03
Claim provenance
Evidence and source independence
2publications detected
2underlying evidence chains
0 primary sources · 0 dependent secondary reports · 2 reports with unresolved independence. Repetition remains visible without multiplying confirmation.
The Hacker News supplied a deterministically extracted signal; review the linked evidence before escalation.
00:0003 Nov
KEV ADDED
CISA KEV entry added
CISA lists global known exploitation. This is not a VTP sensor observation.
05
Original publications
Source record
SecurityWeekPRESSUNKNOWN
Thai Broadband Provider Hacked via Fortinet Vulnerability
The hackers staged numerous scripts for reconnaissance and CVE probing, along with brute-force utilities and privilege escalation tools. The post Thai Broadband Provider Hacked via Fortinet Vulnerability appeared first on SecurityWeek .
FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations
The U.S. Department of Justice (DoJ) on Wednesday announced the disruption of two hacking platforms named QScan and QTRouter operated by Chinese threat actors to target critical infrastructure and other sensitive networks in the country. The activity has been attributed to a Chinese state-sponsored group known as QTFY, employed by Nanjing Xinjiuwei Network Technology Company (南京鑫玖维网络科技有限公司).&
First-party honeypot request semantics are potentially consistent with this CVE. This is an unconfirmed candidate match, not proof of exploitation or successful execution.