HackerFeeds
All CVEs

CVE-2018-13374

MEDIUM4.3
CISA KEV

Published 2019-01-22 · Updated 2026-08-13 · Source psirt@fortinet.com

Description

A Improper Access Control in Fortinet FortiOS 6.0.2, 5.6.7 and before, FortiADC 6.1.0, 6.0.0 to 6.0.1, 5.4.0 to 5.4.4 allows attacker to obtain the LDAP server login credentials configured in FortiGate via pointing a LDAP server connectivity test request to a rogue LDAP server instead of the configured one.

CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CWE-732CWE-732

CISA Known-Exploited Vulnerability

Product: FortinetFortiOS and FortiADC

Name: Fortinet FortiOS and FortiADC Improper Access Control Vulnerability

Date added: 2022-09-08 · Due: 2022-09-29

USED IN RANSOMWARE

Required action: Apply updates per vendor instructions.

View on NVD