CVE-2018-13374
medium · 4.3Actively exploitedOn the CISA Known Exploited Vulnerabilities catalog
Apply updates per vendor instructions.
Added 2022-09-08Remediation due 2022-09-29
A Improper Access Control in Fortinet FortiOS 6.0.2, 5.6.7 and before, FortiADC 6.1.0, 6.0.0 to 6.0.1, 5.4.0 to 5.4.4 allows attacker to obtain the LDAP server login credentials configured in FortiGate via pointing a LDAP server connectivity test request to a rogue LDAP server instead of the configured one.
4.3
CVSS
37.8%
EPSS (exploit prob.)
98th
EPSS percentile
2019-01-22
Published
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Weaknesses
CWE-732
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| fortinet | fortiadc | >= 5.4.0, < 5.4.5 |
| fortinet | fortiadc | >= 6.0.0, < 6.0.2 |
| fortinet | fortiadc | 6.1.0 |
| fortinet | fortios | < 6.0.3 |
Check a specific version with /api/v1/cve/match.
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2018-13374