
CVE-2018-13382
CVE-2018-13382
https://devco.re/blog/2019/08/09/attacking-ssl-vpn-part-2-breaking-the-Fortigate-ssl-vpn/
Fortinet FortiOS 6.0.06.0.4, 5.6.05.6.8 및 5.4.1~5.4.10의 SSL VPN 웹 포털에 존재하는 부적절한 권한 부여 취약점으로 인해, 인증되지 않은 공격자가 특별히 조작된 HTTP 요청을 사용하여 SSL VPN 웹 포털 사용자의 비밀번호를 변경할 수 있습니다.

$ python CVE-2018-13382.py -h
Usage: CVE-2018-13382.py [options]
Options:
-h, --help show this help message and exit
-i IP e.g. 127.0.0.1:10443
-u USERNAME
-p PASSWORD