VYPR
Medium severity5.3NVD Advisory· Published Apr 9, 2019· Updated Jun 17, 2026

CVE-2018-13366

CVE-2018-13366

Description

An information disclosure vulnerability in Fortinet FortiOS 6.0.1, 5.6.7 and below allows attacker to reveals serial number of FortiGate via hostname field defined in connection control setup packets of PPTP protocol.

Affected products

5
  • Fortinet/Fortios4 versions
    cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*range: <=5.6.7
    • cpe:2.3:o:fortinet:fortios:6.0.0:*:*:*:*:*:*:*
    • cpe:2.3:o:fortinet:fortios:6.0.1:*:*:*:*:*:*:*
    • (no CPE)range: 6.0.1, 5.6.7 and below
  • Fortinet/Fortinetcpe-rescue
    Range: 6.0.1

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.