An Improper Authorization vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8 and 5.4.1 to 5.4.10 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7 under SSL VPN web portal allows an unauthenticated attacker to modify the password of an SSL VPN web portal user via specially crafted HTTP requests
AI-assisted analytical recommendationDoes not set factual exploitation state
AI review stateREVIEWED
AI priorityNONE
AI confidence95%
Public exploitation · VTP factKEV
Assessment
CISA KEV lists this FortiOS and FortiProxy SSL VPN flaw as exploited globally, including ransomware use. Crafted HTTP requests can let an unauthenticated attacker change an SSL VPN portal user's password in affected versions.
Why it matters
A compromised VPN account can give an attacker a valid remote-access path.
The exposed SSL VPN web portal is the relevant attack surface.
Evidence
1 record references and 2 source references passed trusted post-response validation. The current deterministic record contains 0 independent evidence groups.
Uncertainties
First-party honeypot request semantics are potentially consistent with this CVE. This is an unconfirmed candidate match, not proof of exploitation or successful execution.
Next watchpoint
If you use affected FortiOS or FortiProxy SSL VPN versions, apply Fortinet's remediation and review portal-user password changes.
Evidence confidence0%Strongest independent active claim
VelocitySTABLEMaterial events only
First-party telemetryFirst-party honeypot request semantics are potentially consistent with this CVE. This is an unconfirmed candidate match, not proof of exploitation or successful execution.
Honeypot request semantics are strongly consistent with CVE-2018-13382. This identifies likely attack intent, not successful exploitation or execution.
CISA KEV lists this vulnerability as known to be exploited globally.
02
EPSS is 0.82; this is predictive context, not exploitation evidence.
03
First-party honeypot request semantics are potentially consistent with this CVE. This is an unconfirmed candidate match, not proof of exploitation or successful execution.
02
Material change ledger
What changed
KEV ADDEDCISA KEV entry added
03
Claim provenance
Evidence and source independence
0publications detected
0underlying evidence chains
0 primary sources · 0 dependent secondary reports · 0 reports with unresolved independence. Repetition remains visible without multiplying confirmation.
04
Event history
Threat timeline
00:0010 Jan
KEV ADDED
CISA KEV entry added
CISA lists global known exploitation. This is not a VTP sensor observation.
First-party honeypot request semantics are potentially consistent with this CVE. This is an unconfirmed candidate match, not proof of exploitation or successful execution.