Skip to content

FortiOS SSL VPN (CVE-2018-13379)

CVE-2018-13379CWE-22OWASP A01:2021CVSS 9.8Updated August 29, 20261 min read

CVE-2018-13379 is a path traversal in the FortiOS SSL VPN that let an unauthenticated attacker request a session file containing usernames and passwords in plain text. The patch shipped in 2019, but lists of harvested credentials still circulate years later and unpatched appliances are still being found.

Affected
FortiOS 5.4.6 to 5.4.12, 5.6.3 to 5.6.7 and 6.0.0 to 6.0.4 with SSL VPN enabled
Patched in
FortiOS 5.4.13, 5.6.14, 6.0.11 and 6.2.8
Actively exploited
yes

Of every vulnerability in this overview this is the oldest, and for that reason the most instructive. The patch has existed since 2019. Yet CVE-2018-13379 turns up year after year in lists of the most routinely exploited vulnerabilities.

What is CVE-2018-13379

The FortiOS SSL VPN portal accepted a filename in the URL without checking that it stayed inside the intended directory. With a sequence of ../ an attacker could break out of that directory and request arbitrary files. That is a classic path traversal.

The file that mattered is called sslvpn_websession. In it the appliance stored the details of active sessions, usernames and passwords in plain text included.

Why this flaw has such a long tail

An ordinary vulnerability disappears with the patch. This one does not. After a single request the attacker no longer needed a vulnerability: they had working credentials. In November 2020 a list of credentials from tens of thousands of Fortinet VPNs was published. Organisations that patched shortly after but left their passwords unchanged remained reachable through the front door.

Who uses it

Both ransomware affiliates and state-linked actors have deployed this flaw, and Western security agencies warned about it repeatedly. The reason is prosaic: it costs no effort, vulnerable appliances still exist, and the payoff is direct VPN access to the internal network.

What to do now

  • Check which FortiOS build your VPN runs and move it to a patched branch.
  • Reset the passwords of every VPN user if the appliance was ever internet-facing while vulnerable.
  • Put multi-factor authentication on every form of remote access. It is the one control that makes a leaked password worthless.
  • Review the VPN logs for sign-ins from unusual locations or outside working hours.

Sources

Frequently asked questions

Why does a 2018 flaw still appear in lists from 2024?

Because the harvested credentials do not expire when the appliance is patched. An organisation that leaked a password in 2020 and never changed it is still exposed today.

What should I do if we were exposed back then?

Patching is step one, but every VPN user password has to be reset and multi-factor authentication has to go on. Otherwise the leaked list stays usable.

How do I know whether our credentials are on such a list?

You rarely can establish that with certainty. Assume they are if the appliance was internet-facing and unpatched at the time.

Related articles

Press / to search · Esc