>> All posts

CVE-2018-13382: Fortinet FortiOS SSL VPN improper authorization — vendor-disputed

The short version: CVE-2018-13382 is a reported improper-authorization flaw in the FortiOS SSL VPN web portal that researchers said could let an unauthenticated attacker change an SSL VPN user's password. Fortinet has publicly disputed that it works as described, and it affects only old, largely end-of-life FortiOS. It's worth remediating if you somehow still run an affected build — but the evidence is contested, so we don't rate it as an emergency. Steady hands.

At a glance

FactDetail
Our severity takeCritical — contested evidence; only end-of-life builds affected (see below)
CVSS v3.1 (NVD)7.5 — High · AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS (Fortinet, CNA)9.1 — Critical · AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
EPSS~82% · 99.60th percentile (2026-07-17)
In CISA KEV?Was listed; subsequently removed amid the vendor dispute (status uncertain — confirm current KEV)
Known exploited?Disputed — Fortinet contests exploitability as described; treat claims with care
Vulnerability typeCWE-863 incorrect authorization → reported unauthenticated password change
Requires authenticated session?No — reported as pre-authentication
AffectedFortiOS 5.4.1–5.4.10, 5.6.0–5.6.8, 6.0.0–6.0.4 (SSL VPN with local auth)
Fixed inFortiOS 5.4.11 · 5.6.9 · 6.0.5 · 6.2.0 and later

What you need to know

The reported flaw sits in the FortiOS SSL VPN portal's handling of authorization. As described by the original researchers, it could allow an unauthenticated attacker to modify the password of an SSL VPN web-portal user via crafted requests — one of a cluster of FortiOS SSL VPN issues disclosed together (alongside CVE-2018-13379).

Two things keep this from being a fire drill:

  • Fortinet disputes it. The vendor's public position is that the flaw does not permit arbitrary password modification in the way the research claimed. NVD carries the entry, but the exploitability is genuinely contested — which is why the scores diverge so widely (NVD 7.5 vs. Fortinet's own CNA 9.1).
  • The affected versions are ancient. Only old FortiOS 5.4/5.6/6.0 branches are in scope, most of which are end-of-life. An estate on any supported FortiOS is not affected.

How serious we see it

Critical — and this is a case where the honest read runs below the paper score, not above it.

When a flaw is vendor-disputed, its practical exploitability is uncertain, and only end-of-life software is affected, we don't cry "Critical" on sight. The reassuring, bounded part is straightforward: if you're on any supported FortiOS build you're not exposed to this at all, and the fix has been available since 2019. Where it stays relevant is the same place its sibling CVE-2018-13379 does — estates running abandoned FortiOS on the internet, which have bigger problems than this single CVE.

Recommendations

  1. Get off end-of-life FortiOS. The real fix is running a supported build — upgrade to 5.4.11 / 5.6.9 / 6.0.5 / 6.2.0 or, better, a current release.
  2. Enforce MFA on the SSL VPN. MFA blunts any credential-manipulation path and is worth doing regardless of this CVE.
  3. Rotate SSL VPN credentials if you have been running an exposed, unpatched legacy appliance — the whole 2018 cluster made credential hygiene the priority.
  4. Harden exposure. Restrict who can reach the SSL VPN portal and keep the management interface off the public internet.
  5. Confirm your exposure first. Verify whether any internet-facing FortiGate is still on an affected legacy build at all.

How BreachRisk sees it

BreachRisk discovers internet-facing FortiGate SSL VPN and management interfaces from little more than your domain, fingerprints the FortiOS version, and flags exposure against known-affected builds. For a version-based, vendor-disputed issue like this one we detect and flag the exposed, affected appliance — and, just as usefully, tell you when you are not affected because you're on a supported build. We don't claim to exploit a contested flaw; we give you the honest exposure picture and let severity reflect the real evidence.

That's the value of an outside-in view here: it puts a disputed legacy CVE in proportion instead of letting a scary score drive a fire drill on software you should simply be retiring.

References

See your cyber risk, proven.