{
    "id": "CVE-2018-13374",
    "published": "2019-01-22 14:29:00",
    "last_modified": "2026-08-13 05:17:15",
    "cvss_score": "4.3",
    "cvss_severity": "MEDIUM",
    "cvss_version": "3.1",
    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
    "cwe": "CWE-732",
    "description": "A Improper Access Control in Fortinet FortiOS 6.0.2, 5.6.7 and before, FortiADC 6.1.0, 6.0.0 to 6.0.1, 5.4.0 to 5.4.4 allows attacker to obtain the LDAP server login credentials configured in FortiGate via pointing a LDAP server connectivity test request to a rogue LDAP server instead of the configured one.",
    "epss_score": "0.37832",
    "epss_percentile": "0.98498",
    "kev": 1,
    "kev_due": "2022-09-29",
    "has_exploit": 1,
    "updated_at": "2026-09-26 18:23:51",
    "priority": {
        "rank": 1,
        "label": "Patch first",
        "why": "On CISA KEV — known exploited in the wild, due 2022-09-29."
    },
    "products": [
        {
            "vendor": "fortinet",
            "product": "fortiadc"
        },
        {
            "vendor": "fortinet",
            "product": "fortios"
        }
    ],
    "kev_detail": {
        "cve_id": "CVE-2018-13374",
        "date_added": "2022-09-08",
        "due_date": "2022-09-29",
        "vendor": "Fortinet",
        "product": "FortiOS and FortiADC",
        "name": "Fortinet FortiOS and FortiADC Improper Access Control Vulnerability",
        "ransomware": 1
    },
    "exploits": [
        {
            "source": "exploit-db",
            "ref_id": "46171",
            "title": "Fortinet FortiGate FortiOS < 6.0.3 - LDAP Credential Disclosure",
            "date": "2019-01-16",
            "url": "https://www.exploit-db.com/exploits/46171"
        }
    ],
    "refs_list": [
        "https://fortiguard.com/advisory/FG-IR-18-157",
        "https://fortiguard.com/advisory/FG-IR-18-157",
        "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-13374"
    ]
}