CVE-2018-13374

medium Fortinet ⚠️ CISA KEV — Exploited in the Wild
CVSS v3 Base Score
4.3
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
EPSS Score
38.1%
Exploitation probability in 30 days
Top 2% most likely to be exploited
Attack Characteristics
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Confidentiality
Low
Integrity
None
Availability
None
Published: January 22, 2019 (2784 days ago)
Last Modified: August 13, 2026
Vendor: Fortinet
Source: NVD

⚠️ CISA Known Exploited Vulnerability

Added to KEV: 2022-09-08
Remediation Due: 2022-09-29 (⚠ 1438d overdue)
Ransomware Campaign: Known

Description

A Improper Access Control in Fortinet FortiOS 6.0.2, 5.6.7 and before, FortiADC 6.1.0, 6.0.0 to 6.0.1, 5.4.0 to 5.4.4 allows attacker to obtain the LDAP server login credentials configured in FortiGate via pointing a LDAP server connectivity test request to a rogue LDAP server instead of the configured one.

CWE

CWE-732

Affected Products

fortinet fortiadcfortinet fortios

References