← All CVEs

CVE-2018-13374

medium · 4.3Actively exploited

On the CISA Known Exploited Vulnerabilities catalog

Apply updates per vendor instructions.

Added 2022-09-08Remediation due 2022-09-29

A Improper Access Control in Fortinet FortiOS 6.0.2, 5.6.7 and before, FortiADC 6.1.0, 6.0.0 to 6.0.1, 5.4.0 to 5.4.4 allows attacker to obtain the LDAP server login credentials configured in FortiGate via pointing a LDAP server connectivity test request to a rogue LDAP server instead of the configured one.

4.3
CVSS
37.8%
EPSS (exploit prob.)
98th
EPSS percentile
2019-01-22
Published

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Weaknesses

CWE-732

Affected products

VendorProductAffected versions
fortinetfortiadc>= 5.4.0, < 5.4.5
fortinetfortiadc>= 6.0.0, < 6.0.2
fortinetfortiadc6.1.0
fortinetfortios< 6.0.3

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2018-13374