CVE-2018-13384
published 2019-06-04CVE-2018-13384: A Host Header Redirection vulnerability in Fortinet FortiOS all versions below 6.0.5 under SSL VPN web portal allows a remote attacker to potentially poison…
PriorityP427medium6.1CVSS 3.0
AVNACLPRNUIRSCCLILAN
EPSS
1.36%
68.6th percentile
A Host Header Redirection vulnerability in Fortinet FortiOS all versions below 6.0.5 under SSL VPN web portal allows a remote attacker to potentially poison HTTP cache and subsequently redirect SSL VPN web portal users to arbitrary web domains.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fortinet | fortinet | — | — |
| fortinet | fortinet_fortios | — | — |
| fortinet | fortios | < 6.0.5 | 6.0.5 |
| fortinet | fortios | — | — |
CVSS provenance
nvdv3.06.1MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Fortinet
A Host Header Redirection vulnerability in Fortinet FortiOS all versions below 6.0.5 under SSL VPN web portal allows a r...
vendor_fortinet·2019-06-04·CVSS 6.1
CVE-2018-13384 [MEDIUM] CWE-601 A Host Header Redirection vulnerability in Fortinet FortiOS all versions below 6.0.5 under SSL VPN web portal allows a r...
FG-IR-19-002: A Host Header Redirection vulnerability in Fortinet FortiOS all versions below 6.0.5 under SSL VPN web portal allows a r...
A Host Header Redirection vulnerability in Fortinet FortiOS all versions below 6.0.5 under SSL VPN web portal allows a remote attacker to potentially poison HTTP cache and subsequently redirect SSL VPN web portal users to arbitrary web domains.
CVEs: CVE-2018-13384
CWEs: CWE-601
CVSS: 6.1 (medium)
Affected products: FortiOS, Fortinet
GHSA
GHSA-rhph-5r83-p3mr: A Host Header Redirection vulnerability in Fortinet FortiOS all versions below 6
ghsa_unreviewed·2022-05-24
CVE-2018-13384 [MEDIUM] CWE-601 GHSA-rhph-5r83-p3mr: A Host Header Redirection vulnerability in Fortinet FortiOS all versions below 6
A Host Header Redirection vulnerability in Fortinet FortiOS all versions below 6.0.5 under SSL VPN web portal allows a remote attacker to potentially poison HTTP cache and subsequently redirect SSL VPN web portal users to arbitrary web domains.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2019-06-04
Published