Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Vulnerabilities CVE-2018-13374

CVE-2018-13374

Medium
Open
KEV
TLP:CLEAR

Fortinet FortiOS and FortiADC Improper Access Control Vulnerability

AI Analysis

No AI analysis yet.

Description

A Improper Access Control in Fortinet FortiOS 6.0.2, 5.6.7 and before, FortiADC 6.1.0, 6.0.0 to 6.0.1, 5.4.0 to 5.4.4 allows attacker to obtain the LDAP server login credentials configured in FortiGate via pointing a LDAP server connectivity test request to a rogue LDAP server instead of the configured one.

Details

CVSS Score
4.3
EPSS Score
38.09%

98.4th percentile

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Confidence
100%
Published
Jan 22, 2019
Last Modified
Aug 13, 2026
CISA KEV
Date Added
Sep 8, 2022
Patch Due
Sep 29, 2022
Used in ransomware campaigns
Required Action
Apply updates per vendor instructions.
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.