CVE-2018-13374
Summary
| CVE | CVE-2018-13374 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-01-22 14:29:00 UTC |
| Updated | 2021-06-03 11:15:00 UTC |
| Description | A Improper Access Control in Fortinet FortiOS 6.0.2, 5.6.7 and before, FortiADC 6.1.0, 6.0.0 to 6.0.1, 5.4.0 to 5.4.4 allows attacker to obtain the LDAP server login credentials configured in FortiGate via pointing a LDAP server connectivity test request to a rogue LDAP server instead of the configured one. |
Risk And Classification
EPSS: 0.380880000 probability, percentile 0.983980000 (date 2026-07-21)
CISA KEV: Listed on 2022-09-08; due 2022-09-29; ransomware use Known
Problem Types: CWE-732
CISA Known Exploited Vulnerability
| Vendor | Fortinet |
|---|---|
| Product | FortiOS and FortiADC |
| Name | Fortinet FortiOS and FortiADC Improper Access Control Vulnerability |
| Required Action | Apply updates per vendor instructions. |
| Notes | https://www.fortiguard.com/psirt/FG-IR-18-157; https://nvd.nist.gov/vuln/detail/CVE-2018-13374 |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Read-only admins can obtain LDAP credentials configured in FortiGate using LDAP test connectivity feature | FortiGuard | CONFIRM | fortiguard.com | Vendor Advisory |
| FortiGate FortiOS < 6.0.3 - LDAP Credential Disclosure - Hardware webapps Exploit | EXPLOIT-DB | www.exploit-db.com | Exploit, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
| CISA Known Exploited Vulnerabilities catalog | CISA | www.cisa.gov | kev |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.