CVE-2018-13379: Fortinet FortiOS SSL VPN path traversal
HoneyLabs honeypots recorded 13 probes matching CVE-2018-13379 from 6 distinct source IP addresses in the last 7 days. Severity is rated critical.
This CVE is on CISA's Known Exploited Vulnerabilities list.
Request paths that identify it
- /remote/fgt_lang
- /remote/fgt_lang?lang=/../../../..//////////dev/cmdb/sslvpn_websession
Addresses probing it
| Source IP | Probes | Network | Country |
|---|---|---|---|
| 5.188.206.202 | 8 | Krez 999 Eood | Bulgaria |
| 45.56.72.142 | 1 | Akamai Connected Cloud | United States |
| 45.79.2.183 | 1 | Akamai Connected Cloud | United States |
| 143.244.148.132 | 1 | DigitalOcean, LLC | United States |
| 45.79.218.244 | 1 | Akamai Connected Cloud | United States |
| 96.126.108.146 | 1 | Akamai Connected Cloud | United States |
Networks it comes from
| ASN | Organisation | Probes | Source IPs |
|---|---|---|---|
| AS200391 | Krez 999 Eood | 8 | 1 |
| AS63949 | Akamai Connected Cloud | 4 | 4 |
| AS14061 | DigitalOcean, LLC | 1 | 1 |
Captured requests
- /remote/fgt_lang?lang=/../../../..//////////dev/cmdb/sslvpn_websession
HTTP client fingerprints (JA4H)
- ge11nn0400_8fd06a127c33
- ge11nn0300_dedeb29cc523
CVE report
CVE report
Open a specific CVE from the CVE tracker.