CVE-2018-13384Open Redirect in Fortinet Fortios

CWE-601Open Redirect4 documents4 sources
Severity
6.1MEDIUMNVD
EPSS
0.3%
top 48.37%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 4
Latest updateMay 24

Description

A Host Header Redirection vulnerability in Fortinet FortiOS all versions below 6.0.5 under SSL VPN web portal allows a remote attacker to potentially poison HTTP cache and subsequently redirect SSL VPN web portal users to arbitrary web domains.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages2 packages

NVDfortinet/fortios< 6.0.5
CVEListV5fortinet/fortinet_fortiosFortiOS all versions below 6.0.5

🔴Vulnerability Details

2
GHSA
GHSA-rhph-5r83-p3mr: A Host Header Redirection vulnerability in Fortinet FortiOS all versions below 62022-05-24
CVEList
CVE-2018-13384: A Host Header Redirection vulnerability in Fortinet FortiOS all versions below 62019-06-04

📋Vendor Advisories

1
Fortinet
A Host Header Redirection vulnerability in Fortinet FortiOS all versions below 6.0.5 under SSL VPN web portal allows a r...2019-06-04
CVE-2018-13384 — Open Redirect in Fortinet Fortios | cvebase