VYPR
Medium severity6.1NVD Advisory· Published Jun 4, 2019· Updated Jun 17, 2026

CVE-2018-13384

CVE-2018-13384

Description

A Host Header Redirection vulnerability in Fortinet FortiOS all versions below 6.0.5 under SSL VPN web portal allows a remote attacker to potentially poison HTTP cache and subsequently redirect SSL VPN web portal users to arbitrary web domains.

Affected products

3
  • Fortinet/Fortios2 versions
    cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:fortinet:fortios:*:*:*:*:*:*:*:*range: <6.0.5
    • (no CPE)range: <6.0.5
  • Fortinet/Fortinetcpe-rescue
    Range: FortiOS all versions below 6.0.5

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.