Security readout for executives and security teams
Plain-English summary
This issue affects Fortinet FortiOS devices and could let an authenticated regular user change device routing settings through the ZebOS component. That can disrupt traffic flow or redirect connectivity. The source bundle does not provide CVSS, a confirmed patch version, or evidence of active exploitation.
Executive priority
Prioritize this for FortiOS environments with multiple administrators, delegated regular users, or sensitive routing dependencies. It is not evidenced as actively exploited in the supplied bundle, but unauthorized route changes can create operational outages or traffic-control risk.
Technical view
CVE-2018-13371 is described as external control of system behavior in FortiOS. An authenticated, regular user may be able to alter routing settings by connecting to ZebOS. Listed affected versions are FortiOS 6.2.0 and below, 5.6.7 and below, and 5.4.10 and below.
Likely exposure
Exposure is most relevant where affected FortiOS devices have regular user accounts or management paths that can reach the ZebOS component. The bundle does not identify specific device models, deployment modes, or remote unauthenticated exposure.
Exploitation context
No KEV listing is present, and the supplied sources do not state active exploitation or public exploit availability. The described attacker already needs authenticated regular-user access, which lowers urgency compared with unauthenticated perimeter flaws but still matters for shared administration environments.
Researcher notes
Evidence is limited to the CVE description and Fortinet reference. The bundle lacks CVSS, CWE, detailed attack path, fixed version data, and exploit-status confirmation. Avoid assuming unauthenticated reachability or a specific remediation beyond vendor guidance.
Mitigation direction
- Check FortiGuard advisory FG-IR-18-230 for vendor-approved fixed releases and guidance.
- Inventory FortiOS versions and prioritize versions listed as affected.
- Restrict nonessential regular-user access to FortiOS management paths.
- Review routing settings for unauthorized or unexpected changes.
- Monitor FortiOS administrative activity until remediation is complete.
Validation and detection
- Identify all FortiOS assets and record running versions.
- Compare versions against 6.2.0 and below, 5.6.7 and below, and 5.4.10 and below.
- Review user roles with access to routing or ZebOS-related management functions.
- Inspect routing configuration history for unauthorized changes.
- Confirm remediation status against Fortinet’s advisory, not inferred version assumptions.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CVE-2018-13371 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Unknown
- CVSS
- Not scored
- Known Exploited
- No
- Published
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS and timeline data
No CVSS vectors or timeline events were available in the normalized CVE source material.
Source materials
- CVE List V5 sourceCVE List V5
- https://fortiguard.com/advisory/FG-IR-18-230CVE reference · x_refsource_MISC
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
