CVE-2018-13374
mediumCVSS v3 Base Score
4.3
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
EPSS Score
38.1%
Exploitation probability in 30 days
Top 2% most likely to be exploited
Attack Characteristics
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Confidentiality
Low
Integrity
None
Availability
None
Published: January 22, 2019 (2784 days ago)
Last Modified: August 13, 2026
Vendor: Fortinet
Source: NVD
⚠️ CISA Known Exploited Vulnerability
Added to KEV: 2022-09-08
Remediation Due: 2022-09-29 (⚠ 1438d overdue)
Ransomware Campaign: Known
Vulnerability Report
Generated by CyberWatcher
Description
A Improper Access Control in Fortinet FortiOS 6.0.2, 5.6.7 and before, FortiADC 6.1.0, 6.0.0 to 6.0.1, 5.4.0 to 5.4.4 allows attacker to obtain the LDAP server login credentials configured in FortiGate via pointing a LDAP server connectivity test request to a rogue LDAP server instead of the configured one.
CWE
CWE-732Affected Products
fortinet fortiadcfortinet fortios