VYPR
Medium severity5.3NVD Advisory· Published Jun 4, 2019· Updated Jun 17, 2026

CVE-2018-13381

CVE-2018-13381

Description

A buffer overflow vulnerability in Fortinet FortiOS 6.0.0 through 6.0.4, 5.6.0 through 5.6.7, 5.4 and earlier versions and FortiProxy 2.0.0, 1.2.8 and earlier versions under SSL VPN web portal allows a non-authenticated attacker to perform a Denial-of-service attack via special craft message payloads.

Affected products

6
  • cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:fortinet:fortiproxy:*:*:*:*:*:*:*:*range: <=1.2.8
    • cpe:2.3:a:fortinet:fortiproxy:2.0.0:*:*:*:*:*:*:*
    • (no CPE)range: 2.0.0, 1.2.8 and earlier
  • Fortinet/Fortios2 versions
    cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*range: <=5.2.14
    • (no CPE)range: 6.0.0-6.0.4, 5.6.0-5.6.7, 5.4 and earlier
  • Fortinet/Fortinet FortiOS and FortiProxyv5
    Range: FortiOS 6.0.0 through 6.0.4, 5.6.0 through 5.6.7, 5.4 and earlier and FortiProxy 2.0.0, 1.2.8 and earlier.

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.