CVE-2018-13381: Fortinet FortiOS

High severity, CVSS 7.5. EPSS: 1.8% chance of exploitation in the next 30 days.

A buffer overflow vulnerability in Fortinet FortiOS 6.0.0 through 6.0.4, 5.6.0 through 5.6.7, 5.4 and earlier versions and FortiProxy 2.0.0, 1.2.8 and earlier versions under SSL VPN web portal allows a non-authenticated attacker to perform a Denial-of-service attack via special craft message payloads.

Affected products

  • Fortinet FortiOS: up to and including 5.2.14; from 5.4.0, up to and including 5.4.12; from 5.6.0, up to and including 5.6.10; from 6.0.0, up to and including 6.0.4
  • Fortinet FortiProxy: up to and including 1.2.8; version 2.0.0 only

Published 2019-06-04. Last modified 2026-06-17.