Commit CVE-2018-13382

This commit is contained in:
Fortinet PSIRT Team 2021-06-02 15:46:14 +02:00
parent 83662755ef
commit 8d90452f25
No known key found for this signature in database
GPG Key ID: A06B38838DC5CE65

View File

@ -15,17 +15,11 @@
"product": {
"product_data": [
{
"product_name": "Fortinet FortiOS",
"product_name": "Fortinet FortiOS, FortiProxy",
"version": {
"version_data": [
{
"version_value": "FortiOS 6.0.0 to 6.0.4"
},
{
"version_value": "5.6.0 to 5.6.8"
},
{
"version_value": "5.4.1 to 5.4.10"
"version_value": "FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8, 5.4.1 to 5.4.10, FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7"
}
]
}
@ -36,6 +30,22 @@
]
}
},
"impact": {
"cvss": {
"attackComplexity": "Low",
"attackVector": "Network",
"availabilityImpact": "None",
"baseScore": 8.9,
"baseSeverity": "High",
"confidentialityImpact": "High",
"integrityImpact": "High",
"privilegesRequired": "None",
"scope": "Unchanged",
"userInteraction": "None",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
"version": "3.1"
}
},
"problemtype": {
"problemtype_data": [
{
@ -56,24 +66,9 @@
"url": "https://fortiguard.com/advisory/FG-IR-18-389"
},
{
"refsource": "BID",
"name": "108697",
"url": "http://www.securityfocus.com/bid/108697"
},
{
"refsource": "MISC",
"name": "https://devco.re/blog/2019/08/09/attacking-ssl-vpn-part-2-breaking-the-Fortigate-ssl-vpn/",
"url": "https://devco.re/blog/2019/08/09/attacking-ssl-vpn-part-2-breaking-the-Fortigate-ssl-vpn/"
},
{
"refsource": "MISC",
"name": "https://i.blackhat.com/USA-19/Wednesday/us-19-Tsai-Infiltrating-Corporate-Intranet-Like-NSA.pdf",
"url": "https://i.blackhat.com/USA-19/Wednesday/us-19-Tsai-Infiltrating-Corporate-Intranet-Like-NSA.pdf"
},
{
"refsource": "MISC",
"name": "http://packetstormsecurity.com/files/160130/Fortinet-FortiOS-6.0.4-Password-Modification.html",
"url": "http://packetstormsecurity.com/files/160130/Fortinet-FortiOS-6.0.4-Password-Modification.html"
"refsource": "CONFIRM",
"name": "https://www.fortiguard.com/psirt/FG-IR-20-231",
"url": "https://www.fortiguard.com/psirt/FG-IR-20-231"
}
]
},
@ -81,7 +76,7 @@
"description_data": [
{
"lang": "eng",
"value": "An Improper Authorization vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8 and 5.4.1 to 5.4.10 under SSL VPN web portal allows an unauthenticated attacker to modify the password of an SSL VPN web portal user via specially crafted HTTP requests."
"value": "An Improper Authorization vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8 and 5.4.1 to 5.4.10 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7 under SSL VPN web portal allows an unauthenticated attacker to modify the password of an SSL VPN web portal user via specially crafted HTTP requests"
}
]
}