CVE-2018-13374
Fortinet FortiOS and FortiADC Improper Access Control Vulnerability
CVSS
4.3
Medium
EPSS
37.8%
p98
KEV
YES
Sep 8, 2022
Exploit Today
80
0-100
Published: Jan 22, 2019 · Last modified: Aug 13, 2026 · CWE-732
Product
Fortinet / FortiOS and FortiADC
Vulnerability
Fortinet FortiOS and FortiADC Improper Access Control Vulnerability
Added to KEV
Sep 8, 2022
Remediate by
Sep 29, 2022
Known ransomware use
Yes
Summary description
Fortinet FortiOS and FortiADC contain an improper access control vulnerability that allows attackers to obtain the LDAP server login credentials configured in FortiGate by pointing a LDAP server connectivity test request to a rogue LDAP server.
Required action
Apply updates per vendor instructions.
Notes
https://www.fortiguard.com/psirt/FG-IR-18-157; https://nvd.nist.gov/vuln/detail/CVE-2018-13374
A Improper Access Control in Fortinet FortiOS 6.0.2, 5.6.7 and before, FortiADC 6.1.0, 6.0.0 to 6.0.1, 5.4.0 to 5.4.4 allows attacker to obtain the LDAP server login credentials configured in FortiGate via pointing a LDAP server connectivity test request to a rogue LDAP server instead of the configured one.