January 10, 2022 · Applied Cybernetics Group
CVE-2018-13382 — Fortinet FortiOS and FortiProxy
known ransomware use
Fortinet FortiOS and FortiProxy Improper Authorization
- Added to KEV
2022-01-10- Federal due date
2022-07-10- Vendor
- Fortinet
- Product
- FortiOS and FortiProxy
- EPSS
- 99.5th percentile (score 0.871, as of
2026-06-08) - NVD CVSS v3.1
- —
- Ransomware use
- Known
- Upstream
- https://nvd.nist.gov/vuln/detail/CVE-2018-13382
CISA short description
An Improper Authorization vulnerability in Fortinet FortiOS and FortiProxy under SSL VPN web portal allows an unauthenticated attacker to modify the password.
Required action
Apply updates per vendor instructions.