CVE-2018-13374 KEV EXPLOIT
4.3
MEDIUM · CVSS 3.1 · EPSS 37.8% (pctl 98)
Patch first
On CISA KEV — known exploited in the wild, due 2022-09-29.
Description
A Improper Access Control in Fortinet FortiOS 6.0.2, 5.6.7 and before, FortiADC 6.1.0, 6.0.0 to 6.0.1, 5.4.0 to 5.4.4 allows attacker to obtain the LDAP server login credentials configured in FortiGate via pointing a LDAP server connectivity test request to a rogue LDAP server instead of the configured one.
Scoring
| CVSS | 4.3 (MEDIUM, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
| EPSS | 37.83% — more likely to be exploited than 98% of all CVEs |
| Weakness | CWE-732 |
| On CISA KEV | yes — remediate by 2022-09-29 |
| Public exploit | yes |
| Published | 2019-01-22 |
| Last modified | 2026-08-13 |
CISA KEV
| Name | Fortinet FortiOS and FortiADC Improper Access Control Vulnerability |
|---|---|
| Added | 2022-09-08 |
| Due | 2022-09-29 |
| Vendor / product | Fortinet / FortiOS and FortiADC |
| Ransomware use | known |
Affected (2)
| Vendor | Product |
|---|---|
| fortinet | fortiadc |
| fortinet | fortios |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Fortinet FortiGate FortiOS < 6.0.3 - LDAP Credential Disclosure | 2019-01-16 |
References
→ the Explorer · watch your stack · NVD