Executive brief
An improper access control vulnerability in Fortinet FortiOS and FortiADC allows an authenticated attacker to obtain configured LDAP server login credentials. This is achieved by redirecting an LDAP server connectivity test request to a rogue LDAP server.
Affected products
- Fortinet FortiOS <= 5.6.7, 6.0.0 to 6.0.2
- Fortinet FortiADC 5.4.0 to 5.4.4, 6.0.0 to 6.0.1, 6.1.0
Timeline
- 2019-01-23: other: Exploit-DB reference added to record
- 2022-09-08: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-09-08: disclosed: NVD publication date