CVE-2018-13371
published 2020-04-02CVE-2018-13371: An external control of system vulnerability in FortiOS may allow an authenticated, regular user to change the routing settings of the device via connecting to…
PriorityP348high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
1.31%
67.2th percentile
An external control of system vulnerability in FortiOS may allow an authenticated, regular user to change the routing settings of the device via connecting to the ZebOS component.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortios | <= 5.4.10 | — |
| fortinet | fortios | — | — |
| fortinet | fortios | 5.6.0 – 5.6.7 | — |
| fortinet | fortios | 6.0.0 – 6.0.2 | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8g7g-r3j2-29p8: An external control of system vulnerability in FortiOS may allow an authenticated, regular user to change the routing settings of the device via conne
ghsa_unreviewed·2022-05-24
CVE-2018-13371 [MEDIUM] GHSA-8g7g-r3j2-29p8: An external control of system vulnerability in FortiOS may allow an authenticated, regular user to change the routing settings of the device via conne
An external control of system vulnerability in FortiOS may allow an authenticated, regular user to change the routing settings of the device via connecting to the ZebOS component.
Fortinet
An external control of system vulnerability in FortiOS may allow an authenticated, regular user to change the routing se...
vendor_fortinet·2020-04-02·CVSS 8.8
CVE-2018-13371 [HIGH] CWE-20 An external control of system vulnerability in FortiOS may allow an authenticated, regular user to change the routing se...
FG-IR-18-230: An external control of system vulnerability in FortiOS may allow an authenticated, regular user to change the routing se...
An external control of system vulnerability in FortiOS may allow an authenticated, regular user to change the routing settings of the device via connecting to the ZebOS component.
CVEs: CVE-2018-13371
CWEs: CWE-20
CVSS: 8.8 (high)
Affected products: FortiOS
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-04-02
Published