CVE-2018-13379Active Exploitation(fortinet / fortios)

MEDIUMCVSS 9.8 · CRITICALCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for fortinet fortios systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.3 to 5.6.7 and 5.4.6 to 5.4.12 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7 under SSL VPN web portal allows an unauthenticated attacker to download system files via special crafted HTTP resource requests.

5.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2022-05-03. Apply updates per vendor instructions.

Weakness type (CWE)
CWE-22

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fortios
  • fortiproxy

Threat summary

  • Active exploitation appears in 2 classified signals
  • Exploit tooling references are present in monitored signal
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 2 signals
  • Exploit tool or code specified in 1 signal
  • Technical details provided in 2 signals
  • General: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-06-27); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
fortiosfortiproxy

1 version affected across 2 products

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-06-27: 1Mentions · 2026-07-01: 1Mentions · 2026-09-02: 1Exploit Tool / Code · 2026-07-01: 1Active Exploitation · 2026-07-01: 1Active Exploitation · 2026-09-02: 1Technical Details · 2026-06-27: 1Technical Details · 2026-07-01: 106-2707-0109-02
Signal classification2 categories
Active Exploitation
266.7%
General
133.3%
Classification over time
DateTotalLabels
2026-06-271
General1
2026-07-011
Active Exploitation1
2026-09-021
Active Exploitation1
Full discourse3 posts
  • DFIR Radar@DFIR_Radar
    Active Exploitation

    FortiBleed: a credential-harvesting and access-brokering campaign compromised roughly 73,000-86,000 internet-facing FortiGate firewalls, roughly 50% of all exposed devices, attributed to a Russian-speaking IAB group Unit 42 dubbed SantaAd. - FortiBleed is not a single CVE. It chains CVE-2018-13379 credential dumps, the Belsen Group's 15,000 FortiGate config-file leak, infostealer logs, and brute-forced password hashes into one industrial-scale operation. No malware touched FortiOS directly: attackers lived off the land using stolen and backdoor credentials plus the built-in FortiOS packet-sniffer command across 24 protocols. - FortiOS stored legacy AK1 (SHA-1) and SH2 (SHA-256) hashes alongside newer PBKDF2 hashes. When upgraded, the old hash was silently preserved in full config backups as an "old password" field for downgrade compatibility but hidden from a standard show config. Attackers rented 40-GPU Hashopolis clusters to crack those SHA-256 hashes at scale. - FortiGate Sniffer acted as an orchestrator: once one device was owned, attackers deployed passive sniffing to every device they accessed, collecting credentials from crossing traffic, not just FortiOS accounts. Victim metadata was enriched via SSL certificate org fields, then sorted by industry and revenue for IAB resale. - DFIR gap: network appliances sit outside EDR, and config-backup access requires super-admin credentials. #DFIR_Radar

    Post summary

    The report details an active credential‑harvesting campaign exploiting FortiGate devices, leveraging known CVEs and built‑in sniffer functionality to exfiltrate credentials at scale, with no de‑emphasis, PoC, or patch info provided.

    21031373
    1.9K followersView on X
  • Chicago Dawg with…@MusktardNCatsup
    Active Exploitation

    (4/6) Security hardware was the door: DOJ says Sichuan Silence hit 81K Sophos firewalls, one at a U.S. agency. QTFY hit DOJ/Fed/NASA via Pulse, tried Fortinet CVE-2018-13379 and used Ivanti zero-days at DOE labs/NIH. Relabeled Fortinet devices reached gov’t users. [2][3][7][9]

    Post summary

    The statement reports active exploitation of security hardware vulnerabilities by Sichuan Silence and QTFY, impacting thousands of Sophos firewalls and several U.S. government entities.

    1001097
    82 followersView on X
  • AHANONYE@Claver042
    General

    CVE-2018-13379 – Fortinet FortiOS SSL VPN Arbitrary File Read and CVE-2020-0796 – Windows SMBGhost Remote Code Execution. This lab strengthens my threat hunting, log analysis, and incident response skills while improving my understanding of real-world attacker techniques.

    Post summary

    The post short‑lists CVE‑2018‑13379 and CVE‑2020‑0796, noting their types for a lab exercise, but contributes no new exploit, patch, or active‑exploitation details.

    1000047
    304 followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
OSfortinetfortios---
Appfortinetfortiproxy---
Appfortinetfortiproxy2.0.0--

Explore more