Skip to content
safemode.space
All incidents
2021-09-07 (approximate)
data exposure

FortiGate SSL-VPN credential disclosure via CVE-2018-13379 (2021)

Confidence in this reading:
high

What happened

On 8 September 2021 Fortinet's Product Security Incident Response Team published a notice that a malicious actor had disclosed SSL-VPN access credentials for 87,000 FortiGate devices. Fortinet stated that the credentials were obtained from systems that remained unpatched against CVE-2018-13379, its advisory FG-IR-18-384, at the time of the actor's scan, and that the vulnerability itself had been resolved in May 2019. CVE-2018-13379 is a path-traversal flaw in the FortiOS SSL-VPN web portal permitting an unauthenticated attacker to read system files, including the session file holding plaintext credentials. Fortinet's guidance was to disable all VPNs until remediation, upgrade to FortiOS 5.4.13, 5.6.14, 6.0.13 or 6.2.9 and above, treat all credentials as potentially compromised and perform an organisation-wide password reset, implement multi-factor authentication, and notify users. BleepingComputer reported the leaked set as roughly 500,000 credential pairs, a count of pairs rather than of devices.

A commodity network-appliance advisory, in this corpus because SPARTA cites it and because the reason it does is sound: ground segments are ordinary enterprise networks with a mission attached, and operator workstations, schedulers, front-end processors and modems sit behind the same remote-access appliances as everyone else's estate. The mission-specific parts of a ground system are not the part that gets compromised first. Two limits belong on the record. No source identifies a space-sector victim among the 87,000 and none is asserted, which is why IA-0007 is rejected rather than mapped. And the causal shape is unusual here: nothing was done to a spacecraft, a link or a mission system, and what is documented is the creation of an initial-access resource rather than its use. The two figures in circulation measure different things, 87,000 devices in the vendor advisory and about 500,000 credential pairs in the trade reporting; this record uses the vendor's.

Attack vector

Internet-wide scanning for FortiGate devices still unpatched against CVE-2018-13379, then exploitation of the FortiOS SSL-VPN web portal path traversal to read the session file containing plaintext credentials.

Operational impact

None reported against any named organisation. What is documented is the creation of a durable initial-access resource: valid SSL-VPN credentials for 87,000 devices, published.

Data compromised

SSL-VPN access credentials for 87,000 FortiGate devices, published by the actor. Reported elsewhere as approximately 500,000 credential pairs.

Disclosed

2021-09-08

SPARTA techniques evidenced

Each row is a technique this record evidences, with the reasoning and the source that attests to it.

What relationship, confidence, and evidence mean on the rows below
Relationship

What kind of link this is between the technique and the target.

Mitigates: the target actively prevents, detects, or recovers from the technique.

Addresses: the target governs the technique or is relevant to it, without interdicting it. Most governance and policy obligations sit here.

Triggers obligation: the technique occurring is what triggers the duty the target imposes.

Relates to: related to the technique, but the target neither interdicts nor governs it. Used sparingly.

Confidence

How strongly the source supports this mapping, not how severe the technique is.

High: the source supports the mapping squarely.

Moderate: supported, with a qualification such as a cross-tactic reading that stays operationally sound.

Low: the source reaches the technique only in part.

Evidence

How close to the source text the mapping was made.

Direct: a verbatim excerpt of the cited source was read against the technique, and the rationale argues from that excerpt.

Derived: the mapping follows from the source's scope or structure, with no on-point excerpt addressing the technique.

Inferred: reached by composition through another framework, or by domain reasoning the source does not support on its face.

Considered and not mapped

These techniques were considered for this record because a source, a related record or SPARTA's own catalogue pointed at them. Each was read against what the sources say and not mapped. The reason is given in full.

  • The credentials would enable this, and for some victims presumably did. No source names a ground system, a mission or an operator among the 87,000. Mapping it would be asserting a consequence nobody has reported.

  • The resource exists; no use of it is documented in these sources.

  • VPN passwords are not cryptographic key material in RD-0003.02's sense, which is about material conferring command or decryption authority. REC-0003.04 is the correct technique and is mapped.

Sources

The published accounts this record rests on. The tier is SafeMode Space's own assessment of the source, and the reason for it is given beside it. What the tiers mean and how they are assigned: the source tiers.

A source is listed when a mapped technique rests on it, or when it disputes the account. One the curators read but neither cited nor recorded as disputing the record is not listed, so an absence here means neither is true rather than that nobody looked.

  • Fortinet · 2021-09-08

    Tier 1: The vendor's own product security incident response notice about its own product, published under its PSIRT process. Authoritative on the affected versions, the CVE, the device count and the remediation; an interested party on framing.

  • BleepingComputer · 2021-09-08

    Tier 3: Security trade press reporting the forum posting. Tier 3: independent of the vendor, but its headline figure counts a different quantity from the vendor's and the discrepancy is not reconciled in either source.

Every source SafeMode Space reproduces, and on what terms: sources and attribution.

Corpus 2026.08.24-1, built 2026-08-24 from 226 techniques, 308 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.