CVE-2018-13379: Fortinet FortiOS SSL VPN Path Traversal Vulnerability

Critical severity, CVSS 9.8. Actively exploited: in CISA KEV since 2021-11-03. EPSS: 100% chance of exploitation in the next 30 days.

An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.3 to 5.6.7 and 5.4.6 to 5.4.12 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7 under SSL VPN web portal allows an unauthenticated attacker to download system files via special crafted HTTP resource requests.

Affected products

  • Fortinet FortiOS: from 5.4.6, before 5.4.13 (fixed in 5.4.13); from 5.6.3, before 5.6.8 (fixed in 5.6.8); from 6.0.0, before 6.0.5 (fixed in 6.0.5)
  • Fortinet FortiProxy: before 1.2.9 (fixed in 1.2.9); version 2.0.0 only

Published 2019-06-04. Last modified 2026-06-17.