Security readout for executives and security teams
Plain-English summary
This flaw lets a malicious DHCP hostname become script content inside Fortinet management logs. The business risk is that an analyst or administrator viewing those logs could trigger attacker-supplied code in their browser. Sources do not provide severity scoring or evidence of active exploitation.
Executive priority
Treat this as a moderate management-plane risk. It is not listed as known exploited in the supplied data, but affected systems process potentially untrusted network data and present it to privileged users. Prioritize inventory and vendor-guided remediation for legacy Fortinet management systems.
Technical view
CVE-2018-13375 is script-tag neutralization failure affecting Fortinet FortiAnalyzer 5.6.0 and below, and FortiManager 5.6.0 and below when FortiAnalyzer functionality is enabled. A DHCP request with malicious script in HOSTNAME can execute when logs are viewed in the affected products.
Likely exposure
Likely exposure is limited to organizations running FortiAnalyzer 5.6.0 or below, or FortiManager 5.6.0 or below with FortiAnalyzer enabled. Risk depends on DHCP log ingestion and whether privileged users view those logs. The bundle does not identify internet-facing exposure.
Exploitation context
The described attack path requires attacker-controlled DHCP HOSTNAME content to reach Fortinet logs, then a user viewing those logs. CISA KEV is false in the bundle, and no provided source states active exploitation. The issue is still operationally relevant because log viewers are commonly used by privileged staff.
Researcher notes
The provided record lacks CVSS, CWE, exploit status, and remediation detail beyond the Fortinet advisory reference. Analysis should stay scoped to DHCP HOSTNAME script execution in FortiAnalyzer/FortiManager log views. Do not assume other Fortinet products or versions are affected without vendor evidence.
Mitigation direction
- Identify FortiAnalyzer and FortiManager versions in production and management networks.
- Prioritize systems at FortiAnalyzer 5.6.0 or below and FortiManager 5.6.0 or below.
- Check Fortinet advisory FG-IR-18-121 for supported fixed versions or vendor mitigations.
- Restrict management interface access to trusted administrative networks.
- Review log-viewing workflows until affected systems are updated or mitigated.
Validation and detection
- Inventory FortiAnalyzer and FortiManager deployments and confirm exact software versions.
- Determine whether FortiManager has FortiAnalyzer features enabled.
- Confirm whether DHCP HOSTNAME values are collected into viewed logs.
- Review administrative access controls for Fortinet management consoles.
- Check vendor advisory status before claiming remediation is complete.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CVE-2018-13375 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Unknown
- CVSS
- Not scored
- Known Exploited
- No
- Published
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS and timeline data
No CVSS vectors or timeline events were available in the normalized CVE source material.
Source materials
- CVE List V5 sourceCVE List V5
- https://fortiguard.com/advisory/FG-IR-18-121CVE reference · x_refsource_CONFIRM
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
