Known Exploited Vulnerabilities CVE-2018-13379 Mappings

An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.3 to 5.6.7 and 5.4.6 to 5.4.12 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7 under SSL VPN web portal allows an unauthenticated attacker to download system files via special crafted HTTP resource requests.

Mappings

Capability ID Capability Description Mapping Type ATT&CK ID ATT&CK Name Notes
CVE-2018-13379 Fortinet FortiOS SSL VPN Path Traversal Vulnerability exploitation_technique T1190 Exploit Public-Facing Application
Comments
This is a path traversal vulnerability that allows adversary to download system files through specially-crafted HTTP requests.
References